CVE-2026-33144 | GPAC MP4Box utils/xml_bin_custom.c gf_xml_parse_bit_sequence_bs out-of-bounds write (GHSA-3jw5-9pmw-vmfg / EUVD-2026-13782)
A vulnerability, which was classified as critical, was found in GPAC. The affected element is the function gf_xml_parse_bit_sequence_bs of the file utils/xml_bin_custom.c of the component MP4Box. The manipulation results in out-of-bounds write.
This vulnerability is identified as CVE-2026-33144. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.