CVE-2026-103227
Received Received - Intake

Buffer Overflow in GPAC DASH Client

Vulnerability report for CVE-2026-103227, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gpac gpac to 26.07.0 (inc)
gpac gpac abi-16.26

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in GPAC up to version 26.07.0, specifically in the DASH Client component. The issue occurs in the gf_dash_resolve_url function of src/media_tools/dash_client.c. When processing data URLs in DASH manifests, the function rewrites these URLs into in-memory gmem:// URLs but fails to resize the buffer properly. This causes a heap buffer overflow when the rewritten URL exceeds the original buffer size.

Detection Guidance

To detect this vulnerability, monitor for crashes or memory corruption errors in GPAC's DASH client module, particularly when processing data:;base64, URLs. Use AddressSanitizer (ASan) during compilation to identify heap-buffer-overflow issues. Check GPAC logs for errors related to buffer overflows in gf_dash_resolve_url.

Impact Analysis

This vulnerability can be exploited remotely to cause memory corruption or crashes in the affected GPAC application. An attacker could potentially execute arbitrary code or trigger denial-of-service conditions by crafting malicious DASH manifests with specially formatted data URLs. Systems processing untrusted media files or streams are at risk.

Mitigation Strategies

Upgrade GPAC to version abi-16.26 or later. Apply the patch from commit 4c8e26f278ff63eec57968f7bc696f604bb0cffd. Disable DASH client processing of data URLs if an upgrade is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103227. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart