CVE-2026-13523 | GPAC up to 26.02.0 ISOBMFF Parser base_encoding.c data amplification (Issue 3588)
A vulnerability, which was classified as problematic, was found in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data.
This vulnerability is registered as CVE-2026-13523. The attack needs to be launched locally. Furthermore, an exploit is available.
A patch should be applied to remediate this issue.
The vendor confirms: “We added a check on inflate output size, if it surpasses 32 times the input size we stop in error. This value could be adjusted later.”VulDB Recent EntriesRead More