Junglewise Threat Intelligence

CVE-2026-50810: GPAC NULL pointer dereference in smooth_parse_stream_index

CVE-2026-50810 · Severity: info · CVSS 5.5 · Published 2026-07-07

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used for processing and converting video files. A vulnerability in its manifest conversion tool allows an attacker to crash the application by providing a specially crafted Smooth Streaming manifest file. This results in a denial of service, potentially disrupting automated media processing workflows or individual user operations.

Technical details

A NULL pointer dereference exists in the `smooth_parse_stream_index()` function within `src/media_tools/mpd.c`. The vulnerability is triggered when processing a Smooth Streaming manifest (`.ismc`) that contains `StreamIndex` timing entries (`c` elements) but lacks a `Url` attribute. In this scenario, `set->segment_template` remains unallocated (NULL), but the parser subsequently attempts to dereference it to access `segment_timeline->entries`. An attacker can exploit this by providing a malformed manifest to `MP4Box` using the `-mpd` command-line argument. The issue was addressed in commit `b35c61f` by adding null guards for the segment template and its associated structures.

Affected products

  • GPAC GPAC v26.02.0 and earlier; master HEAD before commit b35c61f

Timeline

  • 2026-04-04: disclosed: Issue reported on GitHub
  • 2026-07-02: patched: Fix committed to master branch
  • 2026-07-07: advisory: CVE published in NVD

References

Related threats