CVE-2026-71616: Gpac GPAC vulnerability
Published Sep 9, 2026
·Updated
An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gfroutemediacompleteobject(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.
Affected Software
1 affected component
Gpac GPAC
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPACto a version that resolves this vulnerability.Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab
Event History
Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What condition must an attacker reach to trigger the denial of service?
The issue is triggered through the gf_route_media_complete_object() function. The provided data does not specify the input format, delivery vector, or access level required to reach that function.
2
Which source revisions are identified as affected and fixed?
The affected GPAC revision is c2dee3aff638cd96f9617ac5b17dc2868cd90ef3. The issue is fixed in revision 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.