Description
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The flaw is a null pointer dereference in the gf_sg_mfurl_del routine of GPAC MP4Box’s scenegraph module. This defect can cause the application to crash or terminate unexpectedly when the function is invoked with a malformed or absent URL reference. The attack does not provide code execution but destroys process integrity, potentially denying service to legitimate users. The associated weaknesses are identified as CWE-476 (Null Pointer Dereference) and CWE-404 (Broken or Missing Functionality).

Affected Systems

GPAC, particularly the MP4Box component that includes the scenegraph f1219cde are affected; the vendor does not assign specific major/minor numbers due to its rolling release model23 release, which incorporates the patch with identifier 49dee5cad329cfed310c1682703df7daa47df31a, will remove the vulnerability.

Risk and Exploitability

The vulnerability bears a CVSS score of 4.8, EPSS score of < 1%, and is not listed in the CISA KEV catalog. However, the exploit is publicly available and might be used, indicating a potential risk of exploitation in environments where the attacker can run the MP4Box tool locally. Local access is required, so the attack vector is inferred to be local or within an environment where the attacker can run the MP4Box tool. Exploitation would trigger a denial of service condition but would not breach confidentiality or integrity.

Generated by OpenCVE AI on September 15, 2026 at 16:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the GPAC package to version abi-16.23, which includes the patch.
  • Apply the specific commit patch 49dee5cad329cfed310c1682703df7daa47df31a to the source, if upgrading is not possible.
  • Ensure that local execution of MP within a protected environment.

Generated by OpenCVE AI on September 15, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.
Title GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:45:02.921Z

Reserved: 2026-09-12T16:17:11.942Z

Link: CVE-2026-90573

cve-icon Vulnrichment

Updated: 2026-09-16T19:44:40.396Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T18:16:49.780

Modified: 2026-09-16T20:17:40.007

Link: CVE-2026-90573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference