Description
A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 is able to address this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local process crash leading to denial of service
Action: Upgrade
AI Analysis

Impact

The vulnerability is a null pointer dereference in the gf_node_list_add_child function within GPAC’s MP4Box component, triggered when a null child node is added to the scene graph. This flaw causes the application to crash, resulting in a denial of service for the local user executing the code, but it does not provide any remote code execution capability.

Affected Systems

Affected product is GPAC MP4Box as distributed by the GPAC project. Versions up to commit f121 incorporated in version abi‑16.23 and later, which applies commit 49dee5cad329cfed310c1682703df7daa47df31a.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium risk level, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is local only and requires the attacker to have the ability to invoke the function with a null child. While the exploit has been publicly a crafted input or action within the application, making it unlikely to be widely exploited in in the CISA KEV catalog further reduces the perceived threat but does not eliminate the need for remediation.

Generated by OpenCVE AI on September 15, 2026 at 16:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC MP4Box to version abi‑16.23 or later to apply the patch that removes the null pointer dereference
  • Implement input validation to ensure that no null child references are passed to gf_node_list_add_child before the call is made
  • If an upgrade cannot be performed immediately, monitor the application for segmentation faults and limit the use of the vulnerable code path to reduce the impact of a potential crash

Generated by OpenCVE AI on September 15, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 is able to address this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Title GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:25:08.902Z

Reserved: 2026-09-12T16:30:30.092Z

Link: CVE-2026-90576

cve-icon Vulnrichment

Updated: 2026-09-14T15:25:04.687Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:52.997

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference