CVE-2026-103227 Details
Description
A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.
A buffer overflow vulnerability has been identified in GPAC versions prior to 26.07.0, specifically within the DASH client component. The issue arises in the function 'gf_dash_resolve_url' located in 'src/media_tools/dash_client.c'. The vulnerability allows for a heap-based buffer overflow, which can be exploited remotely by manipulating 'data:;base64,' URLs. This exploitation overwrites memory, potentially leading to arbitrary code execution.
Users are advised to upgrade to GPAC version abi-16.26, which addresses the buffer overflow vulnerability by properly resizing the URL buffer before writing the updated data. This version can be downloaded from the GPAC releases page on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gpac/gpac/ | [email protected] | Vendor |
| https://github.com/gpac/gpac/commit/4c8e26f278ff63eec57968f7bc696f604bb0cffd | [email protected] | Source CodeVendor |
| https://github.com/gpac/gpac/issues/3876 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gpac/gpac/pull/3879 | [email protected] | Issue TrackingVendor |
| https://github.com/gpac/gpac/releases/tag/abi-16.26 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-103227 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/955033 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411908 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/411908/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GPAC | >= 26.07.0, <= 26.07.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion