CVE-2026-1416
Severity CVSS v4.0:
MEDIUM
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
26/01/2026
Last modified:
28/01/2026
Description
A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as d45c264c20addf0c1cc05124ede33f8ffa800e68. It is advisable to implement a patch to correct this issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
1.70
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* | 2.4.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



