Divide-by-Zero Vulnerability in GPAC Media Tools by GPAC
CVE-2026-79513

6.5MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-79513?

The divide-by-zero vulnerability in the gf_dash_get_timeline_duration function within GPAC v26.07.0 introduces a risk of Denial of Service (DoS). An attacker can exploit this flaw by sending a crafted MPD SegmentTimeline, leading to unexpected application behavior and potential disruption of service. This issue has been addressed and fixed in the latest releases, ensuring improved security for users.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.