HomeGpacCVE-2026-1418

CVE-2026-1418

MEDIUM
4.8CVSS
Published: 2026-01-26
Updated: 2026-01-28
AI Analysis

Description

A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to out-of-bounds write. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 10c73b82cf0e367383d091db38566a0e4fe71772. It is best practice to apply a patch to resolve this issue.

CVSS Metrics

Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector
local
Complexity
low
Privileges
low
User Action
none
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-119CWE-787CWE-787

Metadata

Primary Vendor
GPAC
Published
1/26/2026
Last Modified
1/28/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

gpac : gpac

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-1418 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com