CVE-2026-39103 Details
Description
Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_strings(), gf_svg_parse_attribute()
A buffer overflow vulnerability has been identified in GPAC, specifically in the SVG parsing functionality. This issue is present in versions prior to the commit that addresses it. The vulnerability allows an attacker to cause a denial-of-service by crafting a specific SVG file that, when processed by the GPAC SVG parser, leads to a heap-buffer-overflow. This out-of-bounds read can be exploited, causing a crash in the application.
Users can update to the latest version of GPAC, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gpac/gpac/issues/3506 | CISA-ADP | Issue TrackingPatchVendor Advisory |
| https://github.com/gpac/gpac/commit/391dc7f4d234988ea0bc3cc294eb725eddf8f702 | [email protected] | Patch |
| https://github.com/gpac/gpac/issues/3506 | [email protected] | Issue TrackingPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| gpac gpac | < 2026-04-01 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | New CVE Received | [email protected] |