Impact
A flaw in the GPAC 26.02.0 Media File Handler causes the function nhmldump_send_frame to dereference a null pointer (CWE‑476) when processing certain media files. The crash shuts down the GPAC process but does not provide remote code execution. The disruption can deny service to applications that rely on GPAC for media handling.
Affected Systems
The vulnerability affects the GPAC project’s Media File Handler component in version 26.02.0. All builds that include the unpatched write_nhml.c code are impacted.
Risk and Exploitability
The CVSS score of 4.8 places the issue in the medium severity range. An EPSS score of < 1% indicates a very low probability of exploitation. The flaw requires local access, enabling processed by GPAC. No remote exploitation path is documented, and the vulnerability is not listed in the CISA KEV catalog, so the overall risk is moderate for environments where local file access is possible. The exploit has been published and may be used.
OpenCVE Enrichment