Null Pointer Dereference in GPAC Media Export Functionality
CVE-2026-1415
Key Information:
Badges
What is CVE-2026-1415?
A null pointer dereference vulnerability exists in the GPAC media handling component, specifically within the gf_media_export_webvtt_metadata function located in the media_export.c file. This issue arises from improper handling of an argument, leading to potential local exploitation. Attackers must have local access to exploit this vulnerability, making it critical for users of affected versions to apply the recently released patch (identifier: af951b892dfbaaa38336ba2eba6d6a42c25810fd) promptly to safeguard their systems from potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GPAC 2.0
GPAC 2.1
GPAC 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
