PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79513 GPAC CVE debrief

A divide-by-zero vulnerability in GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. The vulnerability is fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. This vulnerability affects systems using GPAC v26.07.0, particularly those handling MPD SegmentTimeline data. Defenders should assess exposure and prioritize verification of GPAC v26.07.0 usage. The vulnerability has a medium severity and is categorized as a Denial of Service (DoS) vulnerability.

Vendor
GPAC
Product
GPAC
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-14
Advisory published
2026-09-09
Advisory updated
2026-09-14

Who should care

Defenders of systems using GPAC v26.07.0, especially those handling MPD SegmentTimeline data, should assess exposure and prioritize verification of GPAC v26.07.0 usage. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review GPAC v26.07.0 usage and apply the fix if applicable. They should also monitor MPD SegmentTimeline data for potential abuse and assess system exposure.

Why it matters

CVE-2026-79513 is a medium-severity vulnerability in GPAC v26.07.0 that can cause a Denial of Service (DoS). Defenders of systems using GPAC should assess exposure, prioritize verification, and apply the fix if necessary.

  • Potential Denial of Service (DoS) via crafted MPD SegmentTimeline.
  • Requires verification of GPAC v26.07.0 usage and exposure.
  • Fixing the vulnerability may require updating GPAC to a patched version.

Technical summary

The gf_dash_get_timeline_duration function in src/media_tools/dash_client.c of GPAC v26.07.0 has a divide-by-zero vulnerability. This allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. The vulnerability was fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. The vulnerability affects systems using GPAC v26.07.0, particularly those handling MPD SegmentTimeline data. Defenders should assess exposure and prioritize verification of GPAC v26.07.0 usage. The fix is available in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Defensive priority

Medium priority for systems using GPAC v26.07.0, especially those handling MPD SegmentTimeline data.

Recommended defensive actions

  • Review GPAC v26.07.0 usage and apply the fix from commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640 if applicable.
  • Monitor MPD SegmentTimeline data for potential abuse.
  • Assess system exposure and prioritize verification of GPAC v26.07.0 usage.
  • Verify GPAC v26.07.0 usage in managed environments.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but its impact and affected systems require further verification. The vulnerability was introduced in GPAC v26.07.0 and can be exploited via a crafted MPD SegmentTimeline. Defenders should verify GPAC v26.07.0 usage and assess exposure. The fix is available in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79513 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79513

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79513 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79513

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.