{"id":"CVE-2026-14790","summary":"GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference","details":"A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml.c of the component Media File Handler. Executing a manipulation can lead to null pointer dereference. The attack requires local access. The exploit has been published and may be used. This patch is called bd1d94e70e3bef364c07c5a1d94eca5c9f56e160. A patch should be applied to remediate this issue. The project explains: \"I would consider most of these more as bugs than vulns but anyway they're good to fix\".","modified":"2026-08-12T15:31:25.319267Z","published":"2026-07-06T02:15:09.433Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-404","CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14790.json"},"references":[{"type":"WEB","url":"https://github.com/gpac/gpac/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14790.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14790"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-14790"},{"type":"ADVISORY","url":"https://vuldb.com/submit/850391"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376379"},{"type":"REPORT","url":"https://github.com/gpac/gpac/issues/3596"},{"type":"REPORT","url":"https://vuldb.com/vuln/376379/cti"},{"type":"FIX","url":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"118e60a905878e56dc4f9c5b309143c5f447c702"},{"fixed":"bd1d94e70e3bef364c07c5a1d94eca5c9f56e160"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"26.02.0"},{"last_affected":"26.02.0"}]}}],"versions":["26.02.0","abi-16.17","abi-16.16","abi-16.15","abi-16.14","abi-16.13","abi-16.11","abi-16.10","abi-16.9","abi-16.8","abi-16.7","abi-16.6","v26.02.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14790.json","vanir_signatures_modified":"2026-08-12T15:31:25Z","vanir_signatures":[{"target":{"function":"MergeTrack","file":"src/isomedia/track.c"},"deprecated":false,"digest":{"function_hash":"292307852225962475116221155174120843426","length":28258},"id":"CVE-2026-14790-13b28192","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160"},{"digest":{"function_hash":"16875489534830420929683044329368011269","length":689},"id":"CVE-2026-14790-1b45224e","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"function":"extl_box_read","file":"src/isomedia/box_code_base.c"},"deprecated":false},{"digest":{"line_hashes":["204419296685946106678087887308847468388","159711758644468079927799762023522409080","224460959496885554969065576827989575473","148312186063505015602199732187519120871","220807234953271120204810233456047339778","102936802077202478037188275518908206984"],"threshold":0.9},"id":"CVE-2026-14790-370a3926","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/isomedia/track.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"139415389381239264735786919312399887907","length":4075},"id":"CVE-2026-14790-37eb2925","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/filters/reframe_amr.c","function":"amrdmx_process"}},{"digest":{"line_hashes":["115703475006709578956996545273896487718","264879779534158188067446151504515639941","67869957926113377579703940984784654981","59323866592267896750935194038521751783"],"threshold":0.9},"id":"CVE-2026-14790-3b0a98e0","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/media_tools/av_parsers.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"284126114517388213241160054877653051128","length":3260},"id":"CVE-2026-14790-41eda2ee","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/media_tools/av_parsers.c","function":"gf_vp9_parse_sample"}},{"target":{"file":"src/filters/restamp.c","function":"restamp_configure_pid"},"deprecated":false,"digest":{"function_hash":"327615111502328898979607936703629293985","length":4094},"id":"CVE-2026-14790-4c23e480","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160"},{"id":"CVE-2026-14790-4fb7445c","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/filters/write_nhml.c"},"deprecated":false,"digest":{"line_hashes":["119044031649142180858047144112980846912","320034297899414708230487540441277955567","312284628550402256103530536841011033253","312728671878112940012741880489936533385"],"threshold":0.9}},{"id":"CVE-2026-14790-6e0b2903","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/filters/mux_gsf.c","function":"gsfmx_send_packets"},"deprecated":false,"digest":{"function_hash":"263276535131242964903545519921686761957","length":2707}},{"target":{"file":"src/filters/restamp.c"},"deprecated":false,"digest":{"line_hashes":["297209739703326057908568587246284537133","52988013483287054674608794607241063056","230608769102488337311833923209260038967","317706629457396128028873250870061190866","192451461015037748735238351279367105998"],"threshold":0.9},"id":"CVE-2026-14790-88d06b57","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["112956664125823162831360537713987015118","38575070721493597002660837559179321925","283820792385604487852153915042763843780","45342022621613318314095151506777635985"]},"id":"CVE-2026-14790-8ace4437","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/isomedia/box_code_base.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/media_tools/isom_tools.c","function":"gf_media_split_svc"},"deprecated":false,"digest":{"length":13362,"function_hash":"263787734358302878686838027168811071359"},"id":"CVE-2026-14790-91b68fca"},{"signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/filters/reframe_amr.c"},"deprecated":false,"digest":{"line_hashes":["192984395497762029699852796647053289114","283954893014870594041362760902585554979","49978729751552335365794319066770032887","129230852645280379245481921401923995689","193582838816129293834233500427948183359","7459177025135496756224197795476879607","316311478488419310786204520956394711147","78280314065331534318691714328670471152","53983963471378718617040048137341387360","239432591345893890425056661030670816774","181362103085193834871228659540722465069","41910091076030748071756727870148905357","185283466612593528316473452549954561575"],"threshold":0.9},"id":"CVE-2026-14790-aeb65912","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["127985063796879655180015261352238001920","268445786969101131841631116255018222116","305110257478443466943278821253819823328","90244516026473328061452543706890892313","8913215329959710446461422688935549767","86252479982661106289471008617830543135","309060999460820788696776741131008972727","108823976578592729907300524462088506413","178880856161434447066711345388499508482"],"threshold":0.9},"id":"CVE-2026-14790-b17fd560","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/filters/mux_gsf.c"}},{"signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/filters/write_nhml.c","function":"nhmldump_send_frame"},"deprecated":false,"digest":{"function_hash":"260201978394472503674173478928492504531","length":8427},"id":"CVE-2026-14790-b297f48c","signature_type":"Function"},{"digest":{"line_hashes":["148583584262143698929500877326206028464","333039880542415883002581165960690510769","328581614403379065913138072181203599907","68448767973338772354416159966491587866"],"threshold":0.9},"id":"CVE-2026-14790-ef9fefbc","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/bd1d94e70e3bef364c07c5a1d94eca5c9f56e160","target":{"file":"src/media_tools/isom_tools.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}