Junglewise Threat Intelligence

CVE-2026-79513: GPAC divide-by-zero in dash_client timeline parsing

CVE-2026-79513 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used to play and stream audio and video content. A flaw in how it processes DASH video streaming manifest files (MPD) can be exploited via a crafted manifest to crash the player, causing a denial of service. An attacker hosting a malicious video stream could render playback unavailable for users connecting to it.

Technical details

A divide-by-zero vulnerability exists in the gf_dash_get_timeline_duration function in src/media_tools/dash_client.c. The DASH MPD parser stores segment duration attributes without validating they are non-zero, then later performs division by this duration value when calculating segment counts, triggering a floating-point exception (SIGFPE). The vulnerability is triggered when a crafted MPD file contains a SegmentTimeline element with d="0" (e.g., <S t="0" d="0" r="-1"/>). An attacker can exploit this via network by hosting a malicious MPD file and directing users to stream from it; no authentication or user interaction beyond clicking a link is required. Successful exploitation crashes the GPAC process. A fix has been committed to the repository (commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640).

Affected products

  • GPAC GPAC v26.07.0

Timeline

  • 2026-08-19: disclosed: Security issue reported on GitHub
  • 2026-09-09: advisory: CVE-2026-79513 published
  • 2026: patched: Fix committed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640

References

Related threats