A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79513.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79513.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"180307161740013771970914708679297535556",
"240565326493972235733868205110011386817",
"4945656072147685218395139178465593765",
"257725548577252927012493515558158079076"
],
"threshold": 0.9
},
"id": "CVE-2026-79513-390a7e42",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
"target": {
"file": "src/media_tools/dash_client.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "157006622584405958747276198975724895642",
"length": 2121
},
"id": "CVE-2026-79513-434a397d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
"target": {
"file": "src/utils/downloader.c",
"function": "gf_dm_get_chunk_data"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "218310450480768081407471728584170508622",
"length": 1192
},
"id": "CVE-2026-79513-7c2f2ae3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
"target": {
"file": "src/media_tools/dash_client.c",
"function": "gf_dash_get_timeline_duration"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "25732055345454472386571772859651113206",
"length": 4321
},
"id": "CVE-2026-79513-7dbf7e39",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
"target": {
"file": "src/utils/downloader.c",
"function": "gf_dm_data_received"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"159387710911365815751820360748974025616",
"132311721764338489601677151635024743080",
"208602939837575344339334407286722180769",
"103454766202583253804497015865865112004",
"225321460670839055824897110256177107803",
"300418355107546251657801764087055287924",
"56731842693747205784554929168881012760",
"34764387777568229296860257178399807001",
"48718647234581644717583451115323436984",
"23741182924135824422110119678987360866",
"50106481613325759540098438463271202972",
"261829122287050210835413705101916103544",
"170812779044850876991803915419865268447",
"115693041160905735785684920883853391864",
"16483123015073758990044360012960018271",
"246966326150289473106628762682762738383",
"244672396759951241412913633994037210137",
"127543739089371930598469283287695459405",
"10946870763579832847690120869298012334",
"301493735611327218674933927813248948064"
],
"threshold": 0.9
},
"id": "CVE-2026-79513-7ff6c301",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
"target": {
"file": "src/utils/downloader.c"
}
}
]
"2026-09-12T08:07:29Z"