CVE-2026-79514

Source
https://cve.org/CVERecord?id=CVE-2026-79514
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79514.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79514
Downstream
Published
2026-09-09T00:00:00Z
Modified
2026-09-17T08:07:06Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:R CVSS Calculator
Summary
[none]
Details

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79514.json"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gpac:gpac:26.07.0:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "26.07.0"
        },
        {
            "last_affected":  "26.07.0"
        }
    ],
    "source":  [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

26.*
26.07.0
abi-16.*
abi-16.22
abi-16.23
abi-16.24
abi-16.25
v26.*
v26.07.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79514.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "180307161740013771970914708679297535556",
                "240565326493972235733868205110011386817",
                "4945656072147685218395139178465593765",
                "257725548577252927012493515558158079076"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-79514-390a7e42",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target":  {
            "file":  "src/media_tools/dash_client.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "157006622584405958747276198975724895642",
            "length":  2121
        },
        "id":  "CVE-2026-79514-434a397d",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target":  {
            "file":  "src/utils/downloader.c",
            "function":  "gf_dm_get_chunk_data"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "218310450480768081407471728584170508622",
            "length":  1192
        },
        "id":  "CVE-2026-79514-7c2f2ae3",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target":  {
            "file":  "src/media_tools/dash_client.c",
            "function":  "gf_dash_get_timeline_duration"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "25732055345454472386571772859651113206",
            "length":  4321
        },
        "id":  "CVE-2026-79514-7dbf7e39",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target":  {
            "file":  "src/utils/downloader.c",
            "function":  "gf_dm_data_received"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "159387710911365815751820360748974025616",
                "132311721764338489601677151635024743080",
                "208602939837575344339334407286722180769",
                "103454766202583253804497015865865112004",
                "225321460670839055824897110256177107803",
                "300418355107546251657801764087055287924",
                "56731842693747205784554929168881012760",
                "34764387777568229296860257178399807001",
                "48718647234581644717583451115323436984",
                "23741182924135824422110119678987360866",
                "50106481613325759540098438463271202972",
                "261829122287050210835413705101916103544",
                "170812779044850876991803915419865268447",
                "115693041160905735785684920883853391864",
                "16483123015073758990044360012960018271",
                "246966326150289473106628762682762738383",
                "244672396759951241412913633994037210137",
                "127543739089371930598469283287695459405",
                "10946870763579832847690120869298012334",
                "301493735611327218674933927813248948064"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-79514-7ff6c301",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640",
        "target":  {
            "file":  "src/utils/downloader.c"
        }
    }
]
vanir_signatures_modified
"2026-09-17T08:07:06Z"