CVE-2026-7135

MEDIUM

GPAC MP4Box box_code_base.c elng_box_read out-of-bounds

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-359734 | GPAC MP4Box box_code_base.c elng_box_read out-of-bounds
https://vuldb.com/vuln/359734
Signature, Permissions Required signature permissions-required
VDB-359734 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/359734/cti
Third Party Advisory third-party-advisory
Submit #800985 | gpac laster Memory Corruption
https://vuldb.com/submit/800985
Exploit exploit issue-tracking
https://github.com/gpac/gpac/issues/3516

Scores

CVSS v3 5.3
EPSS 0.0011
EPSS Percentile 1.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-125
Status published
Products (1)
None/GPAC 26.03-DEV-rev105-g8f39a1eb3-master
Published Apr 27, 2026
Tracked Since Apr 27, 2026