CVE-2026-7135
GPAC MP4Box box_code_base.c elng_box_read out-of-bounds
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.
| CWE | CWE-125 CWE-119 |
| Vendor | n/a |
| Product | gpac |
| Published | Apr 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a gpac
Be the first to know when new medium vulnerabilities affecting n/a gpac are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / GPAC
26.03-DEV-rev105-g8f39a1eb3-master
References
vuldb.com: https://vuldb.com/vuln/359734 vuldb.com: https://vuldb.com/vuln/359734/cti vuldb.com: https://vuldb.com/submit/800985 github.com: https://github.com/gpac/gpac/issues/3516 github.com: https://github.com/gpac/gpac/commit/cf6ac48c972eaaee2af270adc3f36615325deb3e github.com: https://github.com/gpac/gpac/releases/tag/abi-16.8 github.com: https://github.com/gpac/gpac/
Credits
๐ Lucian-2333 (VulDB User)