CVE-2026-33144

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c when processing a crafted NHML file containing malicious <BS> (BitSequence) elements. An attacker can exploit this by providing a specially crafted NHML file, causing an out-of-bounds write on the heap. This issue has been via commit 86b0e36.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*

History

14 Apr 2026, 18:21

Type Values Removed Values Added
Summary
  • (es) GPAC es un framework multimedia de código abierto. Antes del commit 86b0e36, se descubrió una vulnerabilidad de desbordamiento de búfer basado en montículo (escritura) en GPAC MP4Box. La vulnerabilidad existe en la función gf_xml_parse_bit_sequence_bs en utils/xml_bin_custom.c al procesar un archivo NHML manipulado que contiene elementos (BitSequence) maliciosos. Un atacante puede explotar esto al proporcionar un archivo NHML especialmente diseñado, causando una escritura fuera de límites en el montículo. Este problema ha sido a través del commit 86b0e36.
References () https://github.com/gpac/gpac/commit/86b0e36ea4c71402fbdaf7e13d73ba8841003e72 - () https://github.com/gpac/gpac/commit/86b0e36ea4c71402fbdaf7e13d73ba8841003e72 - Patch
References () https://github.com/gpac/gpac/security/advisories/GHSA-3jw5-9pmw-vmfg - () https://github.com/gpac/gpac/security/advisories/GHSA-3jw5-9pmw-vmfg - Exploit, Vendor Advisory
CPE cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
First Time Gpac
Gpac gpac

20 Mar 2026, 22:16

Type Values Removed Values Added
References () https://github.com/gpac/gpac/security/advisories/GHSA-3jw5-9pmw-vmfg - () https://github.com/gpac/gpac/security/advisories/GHSA-3jw5-9pmw-vmfg -

20 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 21:17

Updated : 2026-04-14 18:21


NVD link : CVE-2026-33144

Mitre link : CVE-2026-33144

CVE.ORG link : CVE-2026-33144


JSON object : View

Products Affected

gpac

  • gpac
CWE
CWE-787

Out-of-bounds Write