Executive brief
GPAC is a multimedia streaming and transcoding toolkit that processes video and media files. A flaw in the MP4Box component can be triggered by crafting a malicious input file, causing the application to terminate unexpectedly (assertion failure) when processing the file locally. While not a direct data breach, this denial-of-service condition disrupts media processing workflows.
Technical details
This vulnerability is a reachable assertion in the gf_node_get_field_count function within scenegraph/base_scenegraph.c of the MP4Box component. The issue is triggered by local manipulation of input data—an attacker can craft a specially-formed media file that causes the assertion to fail. The vulnerability requires local file access and does not require authentication. A successful exploit results in application termination (denial of service). The issue has been patched in version abi-16.23 (commit 49dee5cad329cfed310c1682703df7daa47df31a).
Affected products
- GPAC GPAC up to f1219cde
Timeline
- 2026-09-14: disclosed
- 2026-07-28: patched