Executive brief
GPAC is an open-source multimedia framework used for processing and converting video files. A vulnerability in its manifest conversion tool allows an attacker to crash the application by providing a specially crafted Smooth Streaming manifest file. This results in a denial of service, potentially disrupting automated media processing workflows or individual user operations.
Technical details
A NULL pointer dereference exists in the `smooth_parse_stream_index()` function within `src/media_tools/mpd.c`. The vulnerability is triggered when processing a Smooth Streaming manifest (`.ismc`) that contains `StreamIndex` timing entries (`c` elements) but lacks a `Url` attribute. In this scenario, `set->segment_template` remains unallocated (NULL), but the parser subsequently attempts to dereference it to access `segment_timeline->entries`. An attacker can exploit this by providing a malformed manifest to `MP4Box` using the `-mpd` command-line argument. The issue was addressed in commit `b35c61f` by adding null guards for the segment template and its associated structures.
Affected products
- GPAC GPAC v26.02.0 and earlier; master HEAD before commit b35c61f
Timeline
- 2026-04-04: disclosed: Issue reported on GitHub
- 2026-07-02: patched: Fix committed to master branch
- 2026-07-07: advisory: CVE published in NVD