Denial of Service Vulnerability in GPAC Media Tools by GPAC
CVE-2026-50810

5.5MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
7 July 2026

What is CVE-2026-50810?

The vulnerability identified in GPAC's media tools involves a NULL pointer dereference in the smooth_parse_stream_index() function located within the src/media_tools/mpd.c file. This flaw can be exploited by attackers, enabling them to create conditions that lead to a denial of service. Specifically, prior to the fix implemented in commit b35c61f104b85fbb16520ac2838d5d2ef70845b5, this vulnerability could disrupt the operation of GPAC, potentially affecting users and services that rely on this software for media processing.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.