CVE-2026-TBD - Use-after-free write in GPAC HTTP input filter error path

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: in_http.c (HTTP input filter) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV; only HEAD is supported per GPAC policy) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3747 closed 2026-07-23 Severity: Critical (9.2): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N Credit: Salim Largo (2ourc3) Description A heap use-after-free write exists in GPAC’s HTTP input filter, in httpin_notify_error(). When the filter’s error-notification path runs during session setup, gf_filter_setup_failure() can tear down the filter (freeing its context), but the function continues to write to that freed context afterward. ...

CVE-2026-TBD - Use-after-free write in GPAC ISOBMFF reader (fragmented MP4)

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: isoffin_read.c (ISOBMFF / MP4 reader filter) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3748 closed 2026-07-23 Severity: High (8.5): CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N Credit: Salim Largo (2ourc3) Description A heap use-after-free write exists in GPAC’s ISOBMFF (MP4/MOV) reader, in isoffin_push_buffer(). While demuxing a crafted fragmented MP4/MOV file, an error branch tears down the reader filter and then keeps writing to the now-freed reader context. ...

CVE-2026-TBD - Use-after-free write in GPAC ISOBMFF reader (moof after mdat)

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: isoffin_read.c (ISOBMFF / MP4 reader filter) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3749 closed 2026-07-23 Severity: High (8.5): CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N Credit: Salim Largo (2ourc3) Description A second heap use-after-free write exists in the same function as the sibling bug at isoffin_read.c:1301, this time in the “unsupported moof-after-mdat” error branch of GPAC’s ISOBMFF reader: a non-fragmented file where a moof box unexpectedly appears after an mdat box, with no file cache available. ...

CVE-2026-TBD - Use-after-free write in GPAC AV1 reframer (OBU parse error)

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: reframe_av1.c (AV1 reframer / demuxer filter) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3744 closed 2026-07-23 Severity: High (7.8 / CVSS 3.1, 8.5 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Credit: Salim Largo (2ourc3) Description A heap use-after-free write exists in GPAC’s AV1 reframer, in av1dmx_check_format(). When OBU (Open Bitstream Unit) parsing fails on a crafted AV1 stream, the filter is torn down via gf_filter_setup_failure(), which can free the demuxer’s context, but the function then writes to that freed context on its way out. ...

CVE-2026-TBD - Use-after-free write in GPAC AV1 reframer (missing temporal delimiter)

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: reframe_av1.c (AV1 reframer / demuxer filter) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3745 closed 2026-07-23 Severity: High (7.8 / CVSS 3.1, 8.5 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Credit: Salim Largo (2ourc3) Description A second heap use-after-free write exists in the same function as the sibling bug at reframe_av1.c:303, this time reached when a stream has no timescale and never carries a temporal delimiter OBU. ...

CVE-2026-TBD - Use-after-free in GPAC filter-session process task

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: filter.c (filter-session core / scheduler) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3746 closed 2026-07-23 Severity: High (7.8 / CVSS 3.1, 8.5 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Credit: Salim Largo (2ourc3) Description A heap use-after-free write exists in the core of GPAC’s filter-session scheduler, in gf_filter_process_task(). If a filter’s own process() callback causes the filter itself to be torn down (e.g. by calling gf_filter_setup_failure() internally), the dispatcher that invoked the callback keeps writing to the now-freed GF_Filter structure once the callback returns. ...

CVE-2026-TBD - Use-after-free read in GPAC filter-session PID init task

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: filter_pid.c (filter-session core / PID resolution) Vulnerability Type: Use-after-free (8-byte pointer read) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3743 closed 2026-07-23 Severity: Medium (5.5 / CVSS 3.1, 6.9 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Credit: Salim Largo (2ourc3) Description A heap use-after-free read exists in GPAC’s filter-session core, in gf_filter_pid_init_task(). While resolving the filter chain for a newly-created PID, the task function can end up dereferencing a PID (or its owning filter) that was freed as part of that same resolution process. ...

CVE-2026-TBD - Heap buffer overflow in GPAC AC-3 bitstream reader

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: bitstream.c (core bitstream reader), reached via the AC-3 parser Vulnerability Type: Heap buffer overflow (1-byte out-of-bounds read) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3740 closed 2026-07-23 Severity: Medium (5.5 / CVSS 3.1, 5.1 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Credit: Salim Largo (2ourc3) Description A heap-buffer-overflow (1-byte out-of-bounds read) exists in GPAC’s core bitstream reader, reachable from the AC-3 audio parser: a bitstream declared larger than its backing allocation reads one byte past the end of that allocation. ...

CVE-2026-TBD - Heap buffer overflow in GPAC BT/XMT scene loader probe

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: load_bt_xmt.c (BT/XMT scene loader format probe) Vulnerability Type: Heap buffer overflow (1-byte out-of-bounds read) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3741 closed 2026-07-23 Severity: Medium (5.5 / CVSS 3.1, 5.1 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Credit: Salim Largo (2ourc3) Description A heap-buffer-overflow (1-byte out-of-bounds read) exists in GPAC’s BT/XMT scene-loader format probe: strncmp reads past the end of the probe buffer when checking for a <!DOCTYPE marker. ...

CVE-2026-TBD - Heap buffer overflow in GPAC H.264/H.265 NALU reframer probe

Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: reframe_nalu.c (H.264/H.265 NALU reframer format probe) Vulnerability Type: Heap buffer overflow (1-byte out-of-bounds read) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3742 closed 2026-07-23 Severity: Medium (5.5 / CVSS 3.1, 5.1 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Credit: Salim Largo (2ourc3) Description A heap-buffer-overflow (1-byte out-of-bounds read) exists in GPAC’s H.264/H.265 NALU reframer format probe: it reads data[1] without first checking that a second byte actually remains in the probe buffer. ...