Junglewise Threat Intelligence

CVE-2026-14801: GPAC TeXML File Handler divide by zero in txtin_probe_duration

CVE-2026-14801 · Severity: low · CVSS 3.3 · Published 2026-07-06

Technologies: Gpac. Vendors: Gpac.

Executive brief

A denial-of-service vulnerability exists in GPAC, a multimedia framework used for video streaming and transcoding. By providing a specially crafted TeXML subtitle file, an attacker can cause the software to crash. This could disrupt media processing workflows or automated video delivery services.

Technical details

A divide-by-zero vulnerability (CWE-369) exists in GPAC's TeXML subtitle import logic within 'src/filters/load_text.c'. The root cause is the 'txtin_texml_setup' function parsing the 'timeScale' attribute from a TeXML file using 'atoi()' without validating that the resulting value is non-zero. This value is subsequently used as a divisor in the 'txtin_probe_duration' function. An attacker can trigger this by providing a TeXML file with 'timeScale="0"', leading to a process crash. A patch has been released in commit 86a5191f2e750c767253e27ed6cfd6d547afebc2.

Affected products

  • GPAC GPAC 26.03-DEV-rev342-g80071f700-master

Timeline

  • 2026-06-05: disclosed: Issue reported on GitHub
  • 2026-07-06: advisory: NVD publication date
  • 2026-07-06: patched: Patch commit identified in advisory

References

Related threats