CVE-2026-13523Exploit

LOWCVSS 1.9 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. This patch is called 297f2d8d1f493d8b241330533cd47f7da758aeb3. A patch should be applied to remediate this issue. The vendor confirms: "We added a check on inflate output size, if it surpasses 32 times the input size we stop in error. This value could be adjusted later."

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404CWE-409

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Exploit: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-29: 1PoC Mentioned / Linked · 2026-06-29: 1Technical Details · 2026-06-29: 106-29
Signal classification1 categories
Exploit
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • Vulmon Vulnerability Feed@VulmonFeeds
    Exploit

    CVE-2026-13523 Buffer Overflow in GPAC ISOBMFF Parser up to 26.02.0 (Public Exploit Ava... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13523 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces that CVE‑2026‑13523 is a buffer overflow in GPAC ISOBMFF Parser (≤26.02.0) and that a public exploit is available, according to the linked vulnerability details.

    01010143
    4.1K followersView on X

Explore more