PatchSiren cyber security CVE debrief
CVE-2026-79513 GPAC CVE debrief
A divide-by-zero vulnerability in GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. The vulnerability is fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. This vulnerability affects systems using GPAC v26.07.0, particularly those handling MPD SegmentTimeline data. Defenders should assess exposure and prioritize verification of GPAC v26.07.0 usage. The vulnerability has a medium severity and is categorized as a Denial of Service (DoS) vulnerability.
- Vendor
- GPAC
- Product
- GPAC
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-14
Who should care
Defenders of systems using GPAC v26.07.0, especially those handling MPD SegmentTimeline data, should assess exposure and prioritize verification of GPAC v26.07.0 usage. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review GPAC v26.07.0 usage and apply the fix if applicable. They should also monitor MPD SegmentTimeline data for potential abuse and assess system exposure.
Why it matters
CVE-2026-79513 is a medium-severity vulnerability in GPAC v26.07.0 that can cause a Denial of Service (DoS). Defenders of systems using GPAC should assess exposure, prioritize verification, and apply the fix if necessary.
- Potential Denial of Service (DoS) via crafted MPD SegmentTimeline.
- Requires verification of GPAC v26.07.0 usage and exposure.
- Fixing the vulnerability may require updating GPAC to a patched version.
Technical summary
The gf_dash_get_timeline_duration function in src/media_tools/dash_client.c of GPAC v26.07.0 has a divide-by-zero vulnerability. This allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. The vulnerability was fixed in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640. The vulnerability affects systems using GPAC v26.07.0, particularly those handling MPD SegmentTimeline data. Defenders should assess exposure and prioritize verification of GPAC v26.07.0 usage. The fix is available in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
Defensive priority
Medium priority for systems using GPAC v26.07.0, especially those handling MPD SegmentTimeline data.
Recommended defensive actions
- Review GPAC v26.07.0 usage and apply the fix from commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640 if applicable.
- Monitor MPD SegmentTimeline data for potential abuse.
- Assess system exposure and prioritize verification of GPAC v26.07.0 usage.
- Verify GPAC v26.07.0 usage in managed environments.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but its impact and affected systems require further verification. The vulnerability was introduced in GPAC v26.07.0 and can be exploited via a crafted MPD SegmentTimeline. Defenders should verify GPAC v26.07.0 usage and assess exposure. The fix is available in commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79513 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79513
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79513 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79513
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/gpac/gpac/commit/2fd5a06ab226767900fd86edb5a1e8bfc1010640
-
Source reference
Unverified legacy reference
URL: https://github.com/gpac/gpac/issues/3862
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.