CVE-2026-1415: GPAC media_export.c gf_media_export_webvtt_metadata null pointer dereference
A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gfmediaexportwebvttmetadata of the file src/mediatools/mediaexport.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is af951b892dfbaaa38336ba2eba6d6a42c25810fd. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1415?
CVE-2026-1415 has been classified with moderate severity due to the potential for denial of service caused by a null pointer dereference.
How do I fix CVE-2026-1415?
To fix CVE-2026-1415, upgrade GPAC to version 2.4.1 or later, where the vulnerability has been addressed.
What versions of GPAC are affected by CVE-2026-1415?
GPAC versions up to and including 2.4.0 are affected by CVE-2026-1415.
What is the impact of CVE-2026-1415?
The impact of CVE-2026-1415 is a potential denial of service due to an application crash resulting from a null pointer dereference.
In which file is CVE-2026-1415 found?
CVE-2026-1415 is found in the file src/media_tools/media_export.c within the GPAC codebase.