CVE-2026-13523 | GPAC up to 26.02.0 ISOBMFF Parser base_encoding.c data amplification (Issue 3588)

SecurityVulns

A vulnerability, which was classified as problematic, was found in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data.

This vulnerability is registered as CVE-2026-13523. The attack needs to be launched locally. Furthermore, an exploit is available.

A patch should be applied to remediate this issue.

The vendor confirms: “We added a check on inflate output size, if it surpasses 32 times the input size we stop in error. This value could be adjusted later.”VulDB Recent EntriesRead More