Impact
An issue in the GPAC media framework allows an attacker to trigger a denial of service by exploiting the gf_route_media_complete_object() function. The flaw causes the process to crash or enter an unrecoverable state when handling certain media routing requests, leading to service interruption or system downtime. This weakness is a case of uncontrolled resource consumption (CWE‑400), where improper handling of input results in excessive or unbounded use of system resources. The vulnerability is present in the GPAC codebase (commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3) and was addressed in commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.
Affected Systems
The flaw applies to any installation running the affected GPAC build identified by commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3. No specific vendor or product version list is supplied by the CNA, so any GPAC deployment using the unpatched code is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.2 classifies the flaw as medium severity, but the EPSS score of under 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver specially crafted media routing requests to the gf_route_media_complete_object() function, typically through a component that processes external media inputs. If executed, the exploit would crash the GPAC process, resulting in a denial of service for the affected application.
OpenCVE Enrichment