A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swfdefbitsjpeg of the file src/scenemanager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as 8961c74f87ae3fe2d3352e622f7730ca96d50cf1. A patch should be applied to remediate this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4185.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.5-DEV-rev2167-gcc9d617c0-master"
},
{
"last_affected": "2.5-DEV-rev2167-gcc9d617c0-master"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-119",
"CWE-121"
]
}"2026-07-22T00:51:49Z"
[
{
"signature_version": "v1",
"target": {
"file": "src/scene_manager/swf_parse.c",
"function": "swf_def_bits_jpeg"
},
"id": "CVE-2026-4185-24ef56f1",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "150048677101715945316070982452165109039",
"length": 3316.0
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
},
{
"signature_version": "v1",
"target": {
"file": "src/scene_manager/swf_parse.c",
"function": "swf_soundstream_hdr"
},
"id": "CVE-2026-4185-429e3022",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "165262283201445446348039112898078129573",
"length": 1273.0
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
},
{
"signature_version": "v1",
"target": {
"file": "src/filters/filelist.c",
"function": "filelist_next_url"
},
"id": "CVE-2026-4185-6580e0c8",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "66394941845096586314385281548696328771",
"length": 9289.0
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
},
{
"signature_version": "v1",
"target": {
"file": "src/scene_manager/swf_parse.c",
"function": "swf_def_sound"
},
"id": "CVE-2026-4185-a0589bd5",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "129001075089916732124817934744052118697",
"length": 1848.0
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
},
{
"signature_version": "v1",
"target": {
"file": "src/scene_manager/swf_parse.c"
},
"id": "CVE-2026-4185-b9609e18",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"148684743387683277115090950399749991638",
"154125711947187791169791995961448844436",
"199390184919938316108811005659277291533",
"42649219165374995751735000465217864496",
"66827706715905267033560963286867236712",
"100954595779061671397179005491091400801",
"210572121385040612696498724699228291935",
"5143718837508651777444020960507887241",
"207132179088097344862659621179346817834",
"74634645313913519452787134262158963533",
"173481528530807392696395114019622161804",
"160808291651776305682769929721015799943",
"185098669973608239734103094356572375671",
"283672981781208373204676337147311506501",
"266560524007023996953180812344663817920",
"284814432627138659010505349600635457834",
"339279936246272503089384681876723641481",
"74334012498907828083910809554627769234",
"152623597756153112905965300857164190521",
"237496809814385834273940120953476401686",
"297444359727222018636137632031714932167",
"164974849028745542112468862470350454299",
"90304048286617672125985685304421828582",
"338546716120359984753024536670864076616",
"107492610951950060959013656478229231325",
"309943058916410400563641152810242232351",
"134523251625350334078766655898473801439",
"22934687722356996168543526328565457216",
"55678183937960771566884840953846596177",
"315079114508221839082633231998858031137",
"310050439120930817914905643059993069058",
"293393821761916385801191965121936320341"
]
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
},
{
"signature_version": "v1",
"target": {
"file": "src/scene_manager/swf_parse.c",
"function": "gf_sm_load_init_swf"
},
"id": "CVE-2026-4185-e6656bc5",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "172369864321035814061149504849502087063",
"length": 2075.0
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
},
{
"signature_version": "v1",
"target": {
"file": "src/filters/filelist.c"
},
"id": "CVE-2026-4185-ec91c80f",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"118000645195368334294995950781810895052",
"219667661957766099497473072214230216712",
"65927849429882626923253835669741717232",
"137078067709997820800787358999371573459"
]
},
"source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4185.json"