PT-2026-53193 · Gpac+1 · Gpac+1

·

CVE-2026-13523

·

Published

2026-06-29

·

Updated

2026-08-18

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GPAC versions prior to 26.02.1
Description A buffer overflow exists in the ISOBMFF Parser component within the src/utils/base encoding.c file. A local attacker can execute a manipulation involving highly compressed data to trigger this issue. The flaw is addressed by implementing a check on the inflate output size, which triggers an error if the output exceeds 32 times the input size.
Recommendations Apply the patch 297f2d8d1f493d8b241330533cd47f7da758aeb3 to remediate the issue.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13523

Affected Products

Gpac
Red Os