CVE-2026-4185

Source
https://cve.org/CVERecord?id=CVE-2026-4185
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4185.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-4185
Downstream
Published
2026-03-15T18:32:08.668Z
Modified
2026-07-22T00:51:49.670568Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow
Details

A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swfdefbitsjpeg of the file src/scenemanager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as 8961c74f87ae3fe2d3352e622f7730ca96d50cf1. A patch should be applied to remediate this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4185.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.5-DEV-rev2167-gcc9d617c0-master"
                },
                {
                    "last_affected": "2.5-DEV-rev2167-gcc9d617c0-master"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-119",
        "CWE-121"
    ]
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.2
abi-16.3
abi-16.4
abi-16.5
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0

Database specific

vanir_signatures_modified
"2026-07-22T00:51:49Z"
vanir_signatures
[
    {
        "signature_version": "v1",
        "target": {
            "file": "src/scene_manager/swf_parse.c",
            "function": "swf_def_bits_jpeg"
        },
        "id": "CVE-2026-4185-24ef56f1",
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "function_hash": "150048677101715945316070982452165109039",
            "length": 3316.0
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/scene_manager/swf_parse.c",
            "function": "swf_soundstream_hdr"
        },
        "id": "CVE-2026-4185-429e3022",
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "function_hash": "165262283201445446348039112898078129573",
            "length": 1273.0
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/filters/filelist.c",
            "function": "filelist_next_url"
        },
        "id": "CVE-2026-4185-6580e0c8",
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "function_hash": "66394941845096586314385281548696328771",
            "length": 9289.0
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/scene_manager/swf_parse.c",
            "function": "swf_def_sound"
        },
        "id": "CVE-2026-4185-a0589bd5",
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "function_hash": "129001075089916732124817934744052118697",
            "length": 1848.0
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/scene_manager/swf_parse.c"
        },
        "id": "CVE-2026-4185-b9609e18",
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "148684743387683277115090950399749991638",
                "154125711947187791169791995961448844436",
                "199390184919938316108811005659277291533",
                "42649219165374995751735000465217864496",
                "66827706715905267033560963286867236712",
                "100954595779061671397179005491091400801",
                "210572121385040612696498724699228291935",
                "5143718837508651777444020960507887241",
                "207132179088097344862659621179346817834",
                "74634645313913519452787134262158963533",
                "173481528530807392696395114019622161804",
                "160808291651776305682769929721015799943",
                "185098669973608239734103094356572375671",
                "283672981781208373204676337147311506501",
                "266560524007023996953180812344663817920",
                "284814432627138659010505349600635457834",
                "339279936246272503089384681876723641481",
                "74334012498907828083910809554627769234",
                "152623597756153112905965300857164190521",
                "237496809814385834273940120953476401686",
                "297444359727222018636137632031714932167",
                "164974849028745542112468862470350454299",
                "90304048286617672125985685304421828582",
                "338546716120359984753024536670864076616",
                "107492610951950060959013656478229231325",
                "309943058916410400563641152810242232351",
                "134523251625350334078766655898473801439",
                "22934687722356996168543526328565457216",
                "55678183937960771566884840953846596177",
                "315079114508221839082633231998858031137",
                "310050439120930817914905643059993069058",
                "293393821761916385801191965121936320341"
            ]
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/scene_manager/swf_parse.c",
            "function": "gf_sm_load_init_swf"
        },
        "id": "CVE-2026-4185-e6656bc5",
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "function_hash": "172369864321035814061149504849502087063",
            "length": 2075.0
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/filters/filelist.c"
        },
        "id": "CVE-2026-4185-ec91c80f",
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "118000645195368334294995950781810895052",
                "219667661957766099497473072214230216712",
                "65927849429882626923253835669741717232",
                "137078067709997820800787358999371573459"
            ]
        },
        "source": "https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4185.json"