CVE-2026-5235

Source
https://cve.org/CVERecord?id=CVE-2026-5235
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5235.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-5235
Published
2026-03-31T22:15:13.447Z
Modified
2026-07-15T01:49:03.590693420Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Axiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow
Details

A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation causes heap-based buffer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5235.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/axiomatic-systems/bento4

Affected ranges

Type
GIT
Repo
https://github.com/axiomatic-systems/bento4
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.6.0-641"
        },
        {
            "last_affected": "1.6.0-641"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.6.0-641
v1.*
v1.6.0-641

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5235.json"