# CVE-2026-46469

## Summary

- **CVE ID:** CVE-2026-46469
- **Severity:** MEDIUM
- **CVSS Score:** 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-369
- **Published:** May 14, 2026
- **Last Modified:** May 14, 2026

## Description

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

## Affected Products

- GStreamer — Good Plug-ins (0)

## References

- [CNA](https://gstreamer.freedesktop.org/security/sa-2026-0018.html)
- [CNA](https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243.patch)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._