PT-2026-4718 · Gpac+1 · Gpac+1

Kery Qi

·

Published

2026-01-26

·

Updated

2026-02-16

·

CVE-2026-1415

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GPAC versions up to 2.4.0
Description A flaw exists in GPAC where manipulation of the Name argument within the gf media export webvtt metadata function, located in the src/media tools/media export.c file, can lead to a null pointer dereference. This issue requires local access to exploit. The exploit is publicly available.
Recommendations Deploy the patch with identifier af951b892dfbaaa38336ba2eba6d6a42c25810fd.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-03616
CVE-2026-1415

Affected Products

Gpac
Red Os