CVE-2026-8124

A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation of resources. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is 442e2299530138d8f874fd885c565ba98a6318ba. It is suggested to install a patch to address this issue.
References
Link Resource
https://github.com/gpac/gpac/ Product
https://github.com/gpac/gpac/commit/442e2299530138d8f874fd885c565ba98a6318ba Patch
https://github.com/gpac/gpac/issues/3519 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/submit/808611 Exploit Third Party Advisory VDB Entry
https://vuldb.com/vuln/361914 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361914/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*

History

14 May 2026, 18:02

Type Values Removed Values Added
References () https://github.com/gpac/gpac/ - () https://github.com/gpac/gpac/ - Product
References () https://github.com/gpac/gpac/commit/442e2299530138d8f874fd885c565ba98a6318ba - () https://github.com/gpac/gpac/commit/442e2299530138d8f874fd885c565ba98a6318ba - Patch
References () https://github.com/gpac/gpac/issues/3519 - () https://github.com/gpac/gpac/issues/3519 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/submit/808611 - () https://vuldb.com/submit/808611 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/361914 - () https://vuldb.com/vuln/361914 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/361914/cti - () https://vuldb.com/vuln/361914/cti - Permissions Required, VDB Entry
First Time Gpac gpac
Gpac
CPE cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*

08 May 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 02:16

Updated : 2026-05-14 18:02


NVD link : CVE-2026-8124

Mitre link : CVE-2026-8124

CVE.ORG link : CVE-2026-8124


JSON object : View

Products Affected

gpac

  • gpac
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling