{"id":"CVE-2026-14801","summary":"GPAC TeXML File load_text.c txtin_probe_duration divide by zero","details":"A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argument txml_timescale leads to divide by zero. An attack has to be approached locally. The name of the patch is 86a5191f2e750c767253e27ed6cfd6d547afebc2. A patch should be applied to remediate this issue.","modified":"2026-07-15T23:33:38.483511Z","published":"2026-07-06T06:15:07.752Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-369","CWE-404"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14801.json","unresolved_ranges":[{"extracted_events":[{"introduced":"26.03-DEV-rev342-g80071f700-master"},{"last_affected":"26.03-DEV-rev342-g80071f700-master"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/gpac/gpac/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14801.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14801"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-14801"},{"type":"ADVISORY","url":"https://vuldb.com/submit/850854"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376395"},{"type":"REPORT","url":"https://github.com/gpac/gpac/issues/3610"},{"type":"REPORT","url":"https://vuldb.com/vuln/376395/cti"},{"type":"FIX","url":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"0"},{"fixed":"86a5191f2e750c767253e27ed6cfd6d547afebc2"}],"database_specific":{"source":"REFERENCES"}}],"versions":["abi-16.17","abi-16.16","abi-16.15","abi-16.14","abi-16.13","abi-16.11","abi-16.10","abi-16.9","abi-16.8","abi-16.7","abi-16.6","v26.02.0","abi-16.5","abi-16.4","abi-16.3","abi-16.2","abi-16","abi-15.2","abi-15.1","abi-15.0","abi-15","abi-14.0","abi-14","abi-13.0","abi-13","abi-12.27","abi-12.26","abi-12.25","abi-12.24","abi-12.23","abi-12.22","abi-12.21","abi-12.20","abi-12.19","abi-12.18","abi-12.17","abi-12.16","abi-12","testtag0.1","v2.2.0","v2.0.0","v1.0.0","v0.9.0","v0.9.0-preview","v0.6.0","v0.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14801.json","vanir_signatures_modified":"2026-07-15T23:33:38Z","vanir_signatures":[{"id":"CVE-2026-14801-236e39e1","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/isomedia/isom_read.c"},"deprecated":false,"digest":{"line_hashes":["169973697478446967026635996914428127328","173332205699571808735417016862651823060","17724232539021276381441696975051315294","44333390121552824897024666327613951078","110500413904893942800943238091893256112"],"threshold":0.9}},{"target":{"file":"src/filters/load_text.c","function":"txtin_probe_duration"},"deprecated":false,"digest":{"function_hash":"296201616841945489801028654479003026079","length":5780},"id":"CVE-2026-14801-40f10db2","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2"},{"digest":{"function_hash":"5647120844940047727203422252987609445","length":2466},"id":"CVE-2026-14801-47ac8830","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/isomedia/isom_read.c","function":"gf_isom_release_segment"},"deprecated":false},{"digest":{"line_hashes":["223532963051212601587577333860825809833","45912967676261999951776995381918752764","161725200790361372484207929744585399766","59929039830255714539883633884316791001","138383601988162985854973638029292634991"],"threshold":0.9},"id":"CVE-2026-14801-482aaca4","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/laser/lsr_dec.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/filters/load_text.c"},"deprecated":false,"digest":{"line_hashes":["298119631557852242737698914490214186837","169443265407777735627765755569351226793","199228053451509444438044603066833553455","29183426652277310059407032539734952111"],"threshold":0.9},"id":"CVE-2026-14801-4d853f4a","signature_type":"Line"},{"target":{"file":"src/utils/bitstream.c","function":"gf_bs_new"},"deprecated":false,"digest":{"function_hash":"79134910230643174910273891939981433693","length":941},"id":"CVE-2026-14801-54c56da6","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2"},{"source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"function":"Media_RewriteODFrame","file":"src/isomedia/media_odf.c"},"deprecated":false,"digest":{"function_hash":"262122537749763954463003878150331713787","length":5475},"id":"CVE-2026-14801-8cd0ad40","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/utils/bitstream.c"},"deprecated":false,"digest":{"line_hashes":["1264265530218981439370435873222610598","42176422920232517908837425314839137357","72150859834834501321142845080322273811","142287560769283630698267475123428483836","325359230312412899483572351862619492974","160121613540282644419792524250574123397","285548955309445481272261232965814637619","132112458209329754441262975095540256587"],"threshold":0.9},"id":"CVE-2026-14801-a015683b","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/laser/lsr_dec.c","function":"lsr_read_id"},"deprecated":false,"digest":{"function_hash":"188556643561276593288810077319830059881","length":2382},"id":"CVE-2026-14801-a98d49e7","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/isomedia/media_odf.c"},"deprecated":false,"digest":{"line_hashes":["37597380410459628765299504098197392982","314518923907443907061223077223397755849","77033215408907174959569731435652259784","31803608325141597184600499448648998623"],"threshold":0.9},"id":"CVE-2026-14801-d05ab581","signature_type":"Line"},{"id":"CVE-2026-14801-e6dcbb8b","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/86a5191f2e750c767253e27ed6cfd6d547afebc2","target":{"file":"src/utils/bitstream.c","function":"gf_bs_write_data"},"deprecated":false,"digest":{"function_hash":"99832640345512242908517363110337249287","length":2651}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}