CVE-2023-39562: Gpac

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

Affected products

  • Gpac Gpac: version 2.3 only

Published 2023-08-28. Last modified 2026-06-17.