CVE-2026-1415
Last modified
CVE-2026-1415 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is af951b892dfbaaa38336ba2eba6d6a42c25810fd. To fix this issue, it is recommended to deploy a patch.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gpac | Gpac | <= 2.4.0 |
References
- https://github.com/gpac/gpac/issues/3428Exploit, Issue Tracking, Vendor Advisory
- https://github.com/gpac/gpac/issues/3428#issue-3802223345Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.342804Permissions Required, VDB Entry
- https://vuldb.com/?id.342804Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.736541Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-1415?
How severe is CVE-2026-1415?
How do I fix CVE-2026-1415?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14144Incorrect security UI in Views in Google Chrome prior to 150…4.2
- CVE-2026-14145Inappropriate implementation in CSS in Google Chrome prior t…6.1
- CVE-2026-14146Inappropriate implementation in CSS in Google Chrome prior t…6.5
- CVE-2026-14147Inappropriate implementation in CSS in Google Chrome prior t…6.1
- CVE-2026-14148Type Confusion in CSS in Google Chrome prior to 150.0.7871.4…6.5
- CVE-2026-14149Use after free in Audio in Google Chrome on Linux prior to 1…8.8
- CVE-2026-14150Insufficient validation of untrusted input in Speech in Goog…5.4
- CVE-2026-14151Inappropriate implementation in AI in Google Chrome prior to…8.3
- CVE-2026-14152Out of bounds read and write in ANGLE in Google Chrome prior…9.6
- CVE-2026-14153Inappropriate implementation in Glic in Google Chrome prior …5.3
- CVE-2026-14154Inappropriate implementation in DevTools in Google Chrome pr…4.8
- CVE-2026-14155Insufficient policy enforcement in StorageAccessAPI in Googl…6.5
Are you affected by CVE-2026-1415?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
