{"id":"CVE-2026-4185","summary":"GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow","details":"A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as 8961c74f87ae3fe2d3352e622f7730ca96d50cf1. A patch should be applied to remediate this issue.","modified":"2026-08-12T16:24:16.276841Z","published":"2026-03-15T18:32:08.668Z","database_specific":{"cwe_ids":["CWE-119","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4185.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.5-DEV-rev2167-gcc9d617c0-master"},{"last_affected":"2.5-DEV-rev2167-gcc9d617c0-master"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/gpac/gpac/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4185.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4185"},{"type":"ADVISORY","url":"https://vuldb.com/?id.351091"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.769840"},{"type":"REPORT","url":"https://github.com/gpac/gpac/issues/3436"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.351091"},{"type":"FIX","url":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1"},{"type":"EVIDENCE","url":"https://github.com/PeterXukt/test_pocs/blob/main/gpac/test.swf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"0"},{"fixed":"8961c74f87ae3fe2d3352e622f7730ca96d50cf1"}],"database_specific":{"source":"REFERENCES"}}],"versions":["abi-16.5","abi-16.4","abi-16.3","abi-16.2","abi-16","abi-15.2","abi-15.1","abi-15.0","abi-15","abi-14.0","abi-14","abi-13.0","abi-13","abi-12.27","abi-12.26","abi-12.25","abi-12.24","abi-12.23","abi-12.22","abi-12.21","abi-12.20","abi-12.19","abi-12.18","abi-12.17","abi-12.16","abi-12","testtag0.1","v2.2.0","v2.0.0","v1.0.0","v0.9.0","v0.9.0-preview","v0.6.0","v0.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4185.json","vanir_signatures_modified":"2026-08-12T16:24:16Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"150048677101715945316070982452165109039","length":3316},"id":"CVE-2026-4185-24ef56f1","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/scene_manager/swf_parse.c","function":"swf_def_bits_jpeg"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/scene_manager/swf_parse.c","function":"swf_soundstream_hdr"},"deprecated":false,"digest":{"function_hash":"165262283201445446348039112898078129573","length":1273},"id":"CVE-2026-4185-429e3022"},{"deprecated":false,"digest":{"function_hash":"66394941845096586314385281548696328771","length":9289},"id":"CVE-2026-4185-6580e0c8","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/filters/filelist.c","function":"filelist_next_url"}},{"deprecated":false,"digest":{"function_hash":"129001075089916732124817934744052118697","length":1848},"id":"CVE-2026-4185-a0589bd5","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/scene_manager/swf_parse.c","function":"swf_def_sound"}},{"deprecated":false,"digest":{"line_hashes":["148684743387683277115090950399749991638","154125711947187791169791995961448844436","199390184919938316108811005659277291533","42649219165374995751735000465217864496","66827706715905267033560963286867236712","100954595779061671397179005491091400801","210572121385040612696498724699228291935","5143718837508651777444020960507887241","207132179088097344862659621179346817834","74634645313913519452787134262158963533","173481528530807392696395114019622161804","160808291651776305682769929721015799943","185098669973608239734103094356572375671","283672981781208373204676337147311506501","266560524007023996953180812344663817920","284814432627138659010505349600635457834","339279936246272503089384681876723641481","74334012498907828083910809554627769234","152623597756153112905965300857164190521","237496809814385834273940120953476401686","297444359727222018636137632031714932167","164974849028745542112468862470350454299","90304048286617672125985685304421828582","338546716120359984753024536670864076616","107492610951950060959013656478229231325","309943058916410400563641152810242232351","134523251625350334078766655898473801439","22934687722356996168543526328565457216","55678183937960771566884840953846596177","315079114508221839082633231998858031137","310050439120930817914905643059993069058","293393821761916385801191965121936320341"],"threshold":0.9},"id":"CVE-2026-4185-b9609e18","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/scene_manager/swf_parse.c"}},{"digest":{"function_hash":"172369864321035814061149504849502087063","length":2075},"id":"CVE-2026-4185-e6656bc5","signature_type":"Function","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/scene_manager/swf_parse.c","function":"gf_sm_load_init_swf"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["118000645195368334294995950781810895052","219667661957766099497473072214230216712","65927849429882626923253835669741717232","137078067709997820800787358999371573459"],"threshold":0.9},"id":"CVE-2026-4185-ec91c80f","signature_type":"Line","signature_version":"v1","source":"https://github.com/gpac/gpac/commit/8961c74f87ae3fe2d3352e622f7730ca96d50cf1","target":{"file":"src/filters/filelist.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}