PT-2026-26668 · Gpac+1 · Gpac+1

·

CVE-2026-33144

·

Published

2026-02-17

·

Updated

2026-06-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPAC versions prior to commit 86b0e36
Description GPAC is an open-source multimedia framework. A heap-based buffer overflow (write) issue exists in GPAC MP4Box within the gf xml parse bit sequence bs function in utils/xml bin custom.c when processing a crafted NHML file containing malicious (BitSequence) elements. An attacker can exploit this by providing a specially crafted NHML file, causing an out-of-bounds write on the heap.
Recommendations Update GPAC to commit 86b0e36 or later.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09345
CVE-2026-33144
GHSA-3JW5-9PMW-VMFG

Affected Products

Gpac
Red Os