Executive brief
A denial-of-service vulnerability exists in GPAC, a multimedia framework used for video streaming and transcoding. By providing a specially crafted TeXML subtitle file, an attacker can cause the software to crash. This could disrupt media processing workflows or automated video delivery services.
Technical details
A divide-by-zero vulnerability (CWE-369) exists in GPAC's TeXML subtitle import logic within 'src/filters/load_text.c'. The root cause is the 'txtin_texml_setup' function parsing the 'timeScale' attribute from a TeXML file using 'atoi()' without validating that the resulting value is non-zero. This value is subsequently used as a divisor in the 'txtin_probe_duration' function. An attacker can trigger this by providing a TeXML file with 'timeScale="0"', leading to a process crash. A patch has been released in commit 86a5191f2e750c767253e27ed6cfd6d547afebc2.
Affected products
- GPAC GPAC 26.03-DEV-rev342-g80071f700-master
Timeline
- 2026-06-05: disclosed: Issue reported on GitHub
- 2026-07-06: advisory: NVD publication date
- 2026-07-06: patched: Patch commit identified in advisory