CVE-2026-39103

Source
https://cve.org/CVERecord?id=CVE-2026-39103
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39103.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-39103
Downstream
Published
2026-05-05T00:00:00Z
Modified
2026-07-21T23:47:39.805590Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svgattributes.c, svgparsestrings(), gfsvgparseattribute()

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39103.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.2
abi-16.3
abi-16.4
abi-16.5
abi-16.6
abi-16.7
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v26.*
v26.02.0

Database specific

vanir_signatures_modified
"2026-07-21T23:47:39Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "src/scenegraph/svg_attributes.c"
        },
        "deprecated": false,
        "source": "https://github.com/gpac/gpac/commit/391dc7f4d234988ea0bc3cc294eb725eddf8f702",
        "id": "CVE-2026-39103-061b920d",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "169520776187051075769360548335254661631",
                "175382046013304064160020499647567451913",
                "306003404104088333798183586222671992921",
                "270993091153340928651994784686335129902",
                "103072224951326357351809013418553238168",
                "330527914961434223182604430356034284340",
                "33197938586015051199028297851939637139",
                "157395375029624462305150796138549892666"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/scenegraph/svg_attributes.c",
            "function": "svg_parse_strings"
        },
        "deprecated": false,
        "source": "https://github.com/gpac/gpac/commit/391dc7f4d234988ea0bc3cc294eb725eddf8f702",
        "id": "CVE-2026-39103-1fd4b28b",
        "signature_version": "v1",
        "digest": {
            "function_hash": "155612511151098599805026098778083652702",
            "length": 591.0
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39103.json"