Buffer Overflow Vulnerability in GPAC DASH Client by GPAC
CVE-2026-103227

5.3MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103227?

A buffer overflow vulnerability has been identified in the GPAC DASH Client, specifically within the gf_dash_resolve_url function located in src/media_tools/dash_client.c. This issue allows an attacker to manipulate the input data remotely, potentially compromising the integrity of the software. It is crucial for users to upgrade to version abi-16.26 to mitigate this vulnerability. The associated patch is identified by the commit hash 4c8e26f278ff63eec57968f7bc696f604bb0cffd.

Affected Version(s)

GPAC 26.07

GPAC abi-16.26

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zzxzzb (VulDB User)
.