PT-2026-4721 · Gpac+1 · Gpac+1

Kery Qi

·

Published

2026-01-26

·

Updated

2026-02-16

·

CVE-2026-1418

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPAC versions up to 2.4.0
Description A security issue exists in GPAC related to the SRT Subtitle Import function. The gf text import srt bifs function within the src/scene manager/text to bifs.c file is susceptible to an out-of-bounds write condition. This manipulation requires local access. The exploit has been publicly disclosed.
Recommendations Apply patch 10c73b82cf0e367383d091db38566a0e4fe71772.

Exploit

Fix

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-03617
CVE-2026-1418

Affected Products

Gpac
Red Os