CVE-2026-79513

Source
https://cve.org/CVERecord?id=CVE-2026-79513
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79513.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79513
Downstream
Published
2026-09-09T00:00:00Z
Modified
2026-09-12T08:07:29Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:R CVSS Calculator
Summary
[none]
Details

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79513.json"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.10
abi-16.11
abi-16.13
abi-16.14
abi-16.15
abi-16.16
abi-16.17
abi-16.18
abi-16.19
abi-16.2
abi-16.20
abi-16.21
abi-16.22
abi-16.23
abi-16.24
abi-16.25
abi-16.3
abi-16.4
abi-16.5
abi-16.6
abi-16.7
abi-16.8
abi-16.9
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v26.*
v26.02.0
v26.07.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79513.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "180307161740013771970914708679297535556",
                "240565326493972235733868205110011386817",
                "4945656072147685218395139178465593765",
                "257725548577252927012493515558158079076"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-79513-390a7e42",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target": {
            "file": "src/media_tools/dash_client.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "157006622584405958747276198975724895642",
            "length": 2121
        },
        "id": "CVE-2026-79513-434a397d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target": {
            "file": "src/utils/downloader.c",
            "function": "gf_dm_get_chunk_data"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "218310450480768081407471728584170508622",
            "length": 1192
        },
        "id": "CVE-2026-79513-7c2f2ae3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target": {
            "file": "src/media_tools/dash_client.c",
            "function": "gf_dash_get_timeline_duration"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "25732055345454472386571772859651113206",
            "length": 4321
        },
        "id": "CVE-2026-79513-7dbf7e39",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target": {
            "file": "src/utils/downloader.c",
            "function": "gf_dm_data_received"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "159387710911365815751820360748974025616",
                "132311721764338489601677151635024743080",
                "208602939837575344339334407286722180769",
                "103454766202583253804497015865865112004",
                "225321460670839055824897110256177107803",
                "300418355107546251657801764087055287924",
                "56731842693747205784554929168881012760",
                "34764387777568229296860257178399807001",
                "48718647234581644717583451115323436984",
                "23741182924135824422110119678987360866",
                "50106481613325759540098438463271202972",
                "261829122287050210835413705101916103544",
                "170812779044850876991803915419865268447",
                "115693041160905735785684920883853391864",
                "16483123015073758990044360012960018271",
                "246966326150289473106628762682762738383",
                "244672396759951241412913633994037210137",
                "127543739089371930598469283287695459405",
                "10946870763579832847690120869298012334",
                "301493735611327218674933927813248948064"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-79513-7ff6c301",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target": {
            "file": "src/utils/downloader.c"
        }
    }
]
vanir_signatures_modified
"2026-09-12T08:07:29Z"