CVE-2026-15185

Source
https://cve.org/CVERecord?id=CVE-2026-15185
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15185.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15185
Downstream
Published
2026-07-09T12:30:08Z
Modified
2026-08-12T15:31:26Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
Details

A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called 532097084729a936bcdf6a27c41003f3bd7dc3ff. It is best practice to apply a patch to resolve this issue. Two different commits were applied to fix this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15185.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "26.03-DEV"
                },
                {
                    "last_affected": "26.03-DEV"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.10
abi-16.11
abi-16.13
abi-16.14
abi-16.15
abi-16.16
abi-16.17
abi-16.2
abi-16.3
abi-16.4
abi-16.5
abi-16.6
abi-16.7
abi-16.8
abi-16.9
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v26.*
v26.02.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15185.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "336089841777024238286693937309490120227",
                "322429913444232431157056766171579038166",
                "287639849339060665885529273960141754910",
                "328389975591734511543449906179852589853",
                "251953984814102445653570954783493285840",
                "173486965457874856082121501348061112907",
                "187897414586635820933277731192766954278",
                "331162067297009591099188024601637682137"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-15185-4151aa84",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aa0fb77b82e51b159a2024c440cdf6b571b14d81",
        "target": {
            "file": "src/media_tools/vobsub.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "125663485791016797248560160241717962536",
            "length": 1803
        },
        "id": "CVE-2026-15185-578241a2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/532097084729a936bcdf6a27c41003f3bd7dc3ff",
        "target": {
            "file": "src/filters/dmx_vobsub.c",
            "function": "vobsubdmx_configure_pid"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "297269921695976566646054331419288808341",
            "length": 4458
        },
        "id": "CVE-2026-15185-6be0aedd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/aa0fb77b82e51b159a2024c440cdf6b571b14d81",
        "target": {
            "file": "src/media_tools/vobsub.c",
            "function": "vobsub_read_idx"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "80134836438023884657358517634165691307",
                "85210374358507921323878689335975062192",
                "175117288876550080737716442135952538294",
                "14565527087967471796698106146777738764",
                "183963763197554090278334178219563432989",
                "23567834368664265913315221581875543619",
                "326545734484740374118770873919729315174",
                "214686141114283194608108986819017885042"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-15185-96716ef5",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/532097084729a936bcdf6a27c41003f3bd7dc3ff",
        "target": {
            "file": "src/filters/dmx_vobsub.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:31:26Z"