A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called 532097084729a936bcdf6a27c41003f3bd7dc3ff. It is best practice to apply a patch to resolve this issue. Two different commits were applied to fix this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15185.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "26.03-DEV"
},
{
"last_affected": "26.03-DEV"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15185.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"336089841777024238286693937309490120227",
"322429913444232431157056766171579038166",
"287639849339060665885529273960141754910",
"328389975591734511543449906179852589853",
"251953984814102445653570954783493285840",
"173486965457874856082121501348061112907",
"187897414586635820933277731192766954278",
"331162067297009591099188024601637682137"
],
"threshold": 0.9
},
"id": "CVE-2026-15185-4151aa84",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/aa0fb77b82e51b159a2024c440cdf6b571b14d81",
"target": {
"file": "src/media_tools/vobsub.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "125663485791016797248560160241717962536",
"length": 1803
},
"id": "CVE-2026-15185-578241a2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/532097084729a936bcdf6a27c41003f3bd7dc3ff",
"target": {
"file": "src/filters/dmx_vobsub.c",
"function": "vobsubdmx_configure_pid"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "297269921695976566646054331419288808341",
"length": 4458
},
"id": "CVE-2026-15185-6be0aedd",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/aa0fb77b82e51b159a2024c440cdf6b571b14d81",
"target": {
"file": "src/media_tools/vobsub.c",
"function": "vobsub_read_idx"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"80134836438023884657358517634165691307",
"85210374358507921323878689335975062192",
"175117288876550080737716442135952538294",
"14565527087967471796698106146777738764",
"183963763197554090278334178219563432989",
"23567834368664265913315221581875543619",
"326545734484740374118770873919729315174",
"214686141114283194608108986819017885042"
],
"threshold": 0.9
},
"id": "CVE-2026-15185-96716ef5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/532097084729a936bcdf6a27c41003f3bd7dc3ff",
"target": {
"file": "src/filters/dmx_vobsub.c"
}
}
]
"2026-08-12T15:31:26Z"