CVE-2026-71616

Source
https://cve.org/CVERecord?id=CVE-2026-71616
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71616.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71616
Downstream
Published
2026-09-09T00:00:00Z
Modified
2026-09-11T09:01:28Z
Summary
[none]
Details

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71616.json"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.10
abi-16.11
abi-16.13
abi-16.14
abi-16.15
abi-16.16
abi-16.17
abi-16.2
abi-16.3
abi-16.4
abi-16.5
abi-16.6
abi-16.7
abi-16.8
abi-16.9
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v26.*
v26.02.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71616.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "139295890546346678362110986314732166913",
            "length": 4373
        },
        "id": "CVE-2026-71616-11619ffd",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/3c4e6c5b3e0c6fa9b16d55599701a08354538fab",
        "target": {
            "file": "src/media_tools/route_dmx.c",
            "function": "gf_route_dmx_push_object"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319377892482981435482126018790024310294",
            "length": 13378
        },
        "id": "CVE-2026-71616-2aebc35e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/3c4e6c5b3e0c6fa9b16d55599701a08354538fab",
        "target": {
            "file": "src/media_tools/route_dmx.c",
            "function": "gf_route_service_setup_stsid"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "163350554568704311823722978293350807049",
            "length": 618
        },
        "id": "CVE-2026-71616-518f4261",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/3c4e6c5b3e0c6fa9b16d55599701a08354538fab",
        "target": {
            "file": "src/media_tools/route_dmx.c",
            "function": "gf_route_route_session_del"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "62360411296869823557877198187938208615",
                "189297240148521038546761968515936171095",
                "207028460080489065570821306088607206206",
                "269710613239947874672102674181056487749",
                "39485754263250342532617249854697325398",
                "271241474977190260002021364739210941733",
                "276493807185486709588453225014282262791",
                "73355623764235184745848705622385543743",
                "284381400379211599364901571075097748815",
                "66129195967997358602335632505340663233",
                "276493807185486709588453225014282262791",
                "73355623764235184745848705622385543743",
                "233371694556804063929208489703635186880",
                "148615117680510721636894508963554081570",
                "252533550576210316380669828433823037381",
                "86321314499330659957606769742429372953",
                "193309541810188249436937145018788713752",
                "90106905375002212538239418198954504732",
                "92796018211055950070503793621868928459",
                "293055884144753961160576813329986000548",
                "11164573337158301814123633461000385428",
                "210103512300571870424231025300022874923",
                "40955913184654600120455178748223227348",
                "6480148408039237439381607916723261512",
                "262372932684203342569324342224061930174",
                "27102745877840214134018393358355624604",
                "91056631030740173930065207513718904922",
                "204768030499594847077235891559507271899",
                "178817450734471322439770474420475480715",
                "62848977826983945078798780873332314204"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-71616-89afc187",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/3c4e6c5b3e0c6fa9b16d55599701a08354538fab",
        "target": {
            "file": "src/media_tools/route_dmx.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "340000342180271403920170354711813300978",
            "length": 1053
        },
        "id": "CVE-2026-71616-a7aa566a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/3c4e6c5b3e0c6fa9b16d55599701a08354538fab",
        "target": {
            "file": "src/media_tools/route_dmx.c",
            "function": "gf_route_lct_removed"
        }
    }
]
vanir_signatures_modified
"2026-09-11T09:01:28Z"