Description
An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.
Published: 2026-09-09
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

An issue in the GPAC media framework allows an attacker to trigger a denial of service by exploiting the gf_route_media_complete_object() function. The flaw causes the process to crash or enter an unrecoverable state when handling certain media routing requests, leading to service interruption or system downtime. This weakness is a case of uncontrolled resource consumption (CWE‑400), where improper handling of input results in excessive or unbounded use of system resources. The vulnerability is present in the GPAC codebase (commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3) and was addressed in commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

Affected Systems

The flaw applies to any installation running the affected GPAC build identified by commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3. No specific vendor or product version list is supplied by the CNA, so any GPAC deployment using the unpatched code is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.2 classifies the flaw as medium severity, but the EPSS score of under 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver specially crafted media routing requests to the gf_route_media_complete_object() function, typically through a component that processes external media inputs. If executed, the exploit would crash the GPAC process, resulting in a denial of service for the affected application.

Generated by OpenCVE AI on September 21, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GPAC to the patched commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab or a later release that incorporates the fix.
  • If an update is not feasible, restrict access to the media routing interfaces to trusted users or isolate GPAC from untrusted inputs.
  • Monitor GPAC logs for unexpected crashes or abnormal resource usage, and apply hardening such as input validation and resource limits to mitigate denial of service risk.

Generated by OpenCVE AI on September 21, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title GPAC Denial of Service via Media Routing Function

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Gpac
Gpac gpac
Vendors & Products Gpac
Gpac gpac

Wed, 09 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title GPAC Denial of Service via Media Routing Function
Weaknesses CWE-400

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T12:21:11.625Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71616

cve-icon Vulnrichment

Updated: 2026-09-14T12:20:37.378Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T20:20:22.003

Modified: 2026-09-14T13:18:44.673

Link: CVE-2026-71616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption