CVE-2026-15185
Severity CVSS v4.0:
LOW
Type:
CWE-119
Buffer Errors
Publication date:
09/07/2026
Last modified:
09/07/2026
Description
A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called 532097084729a936bcdf6a27c41003f3bd7dc3ff. It is best practice to apply a patch to resolve this issue. Two different commits were applied to fix this issue.
Impact
Base Score 4.0
1.90
Severity 4.0
LOW
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
1.70
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://github.com/gpac/gpac/
- https://github.com/gpac/gpac/commit/532097084729a936bcdf6a27c41003f3bd7dc3ff
- https://github.com/gpac/gpac/commit/aa0fb77b82e51b159a2024c440cdf6b571b14d81
- https://github.com/gpac/gpac/issues/3611
- https://vuldb.com/cve/CVE-2026-15185
- https://vuldb.com/submit/851214
- https://vuldb.com/vuln/377111
- https://vuldb.com/vuln/377111/cti


