CVE-2026-1415

LOW

gpac < 2.4.0 - Null Pointer Dereference in gf_media_export_webvtt_metadata

Title source: llm
STIX 2.1

Description

A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is af951b892dfbaaa38336ba2eba6d6a42c25810fd. To fix this issue, it is recommended to deploy a patch.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.342804
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.342804
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.736541
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://github.com/gpac/gpac/issues/3428
Exploit, Issue Tracking, Vendor Advisory exploit issue-tracking
https://github.com/gpac/gpac/issues/3428#issue-3802223345
Various Sources product
https://github.com/gpac/gpac/

Scores

CVSS v3 3.3
EPSS 0.0015
EPSS Percentile 4.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476
Status published
Products (1)
gpac/gpac < 2.4.0
Published Jan 26, 2026
Tracked Since Feb 18, 2026