Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14801— GPAC TeXML File load_text.c txtin_probe_duration divide by zero

CVSS 3.3 · Low EPSS 0.11% · P2

Affected Version Matrix 1

VendorProductVersion RangeStatus
n/aGPAC26.03-DEV-rev342-g80071f700-masteraffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-14801

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GPAC TeXML File load_text.c txtin_probe_duration divide by zero
Source: CVE Program / CVE List V5
Vulnerability Description
A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argument txml_timescale leads to divide by zero. An attack has to be approached locally. The name of the patch is 86a5191f2e750c767253e27ed6cfd6d547afebc2. A patch should be applied to remediate this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
除零错误
Source: CVE Program / CVE List V5
Vulnerability Title
GPAC 数字错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GPAC是GPAC团队开源的一款开源的多媒体框架。 GPAC 26.03-DEV-rev342-g80071f700-master版本存在安全漏洞,该漏洞源于TeXML File Handler组件src/filters/load_text.c文件中函数txtin_probe_duration对参数txml_timescale的操作导致除零错误,可能导致本地攻击者利用该漏洞造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-GPAC 26.03-DEV-rev342-g80071f700-master cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-14801

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14801

登录查看更多情报信息。

Patches & Fixes for CVE-2026-14801 (1)

Vendor Advisories for CVE-2026-14801 (1)

Same Patch Batch · n/a · 2026-07-06 · 8 CVEs total

CVE-2026-147926.5 MEDIUMFormbricks Survey actions.ts access control
CVE-2025-156683.3 LOWGPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
CVE-2025-156673.3 LOWGPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
CVE-2026-147903.3 LOWGPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference
CVE-2026-38976Hayato Ishida mruby/c 安全漏洞
CVE-2026-38973Hayato Ishida mruby/c 安全漏洞
CVE-2026-38979Ajenti Project Ajenti 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-14801

No comments yet


Leave a comment