{"id":"CVE-2026-103227","summary":"GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow","details":"A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.","modified":"2026-10-04T02:30:58.596574037Z","published":"2026-09-30T14:30:09.232Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103227.json"},"references":[{"type":"WEB","url":"https://github.com/gpac/gpac/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103227.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103227"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-103227"},{"type":"ADVISORY","url":"https://vuldb.com/submit/955033"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/411908"},{"type":"REPORT","url":"https://github.com/gpac/gpac/issues/3876"},{"type":"REPORT","url":"https://vuldb.com/vuln/411908/cti"},{"type":"FIX","url":"https://github.com/gpac/gpac/commit/4c8e26f278ff63eec57968f7bc696f604bb0cffd"},{"type":"FIX","url":"https://github.com/gpac/gpac/pull/3879"},{"type":"FIX","url":"https://github.com/gpac/gpac/releases/tag/abi-16.26"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"a07cbfff238a331233e11e916f9fb185d5da8604"},{"fixed":"4c8e26f278ff63eec57968f7bc696f604bb0cffd"},{"fixed":"c1a7cf55f59ef7954939c44f6b24b95c54469214"}],"database_specific":{"extracted_events":[{"introduced":"26.07"},{"last_affected":"26.07"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["26.07","abi-16.25","abi-16.24","abi-16.23","abi-16.22","v26.07.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103227.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}