Description
A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Heap-based Buffer Overflow (Local)
Action: Apply Patch
AI Analysis

Impact

A local heap-based buffer overflow occurs inside the gf_node_get_field routine of GPAC's MP4Box component. The flaw is triggered by malicious input that causes the function to write beyond the bounds of a heap buffer, resulting in CWE-119 and CWE-122 and can lead to crashes or altered program behavior, although arbitrary code execution is not guaranteed by the description.

Affected Systems

GPAC releases up to commit f in scenegraph/base_scenegraph.c, are affected. All installations running a version earlier than abi-16.23 are susceptible. The official fix is delivered by the patch commit 49dee5cad329cfed310c1682703df7daa47df31a, incorporated in the abi-16.23 release.

Risk and Exploitability

The CVSS base score of 4.8 indicates a moderate severity. The EPSS score is less than 1%, showing that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local, with crafted input. Because the exploitation is possible only on systems that run the vulnerable component, the overall risk remains moderate but timely remediation is still recommended.

Generated by OpenCVE AI on September 15, 2026 at 17:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi-16.23 or later, which includes the heap-overflow fix.
  • If an upgrade is not immediately possible, download and apply patch commit 49dee5cad329cfed310c1682703df7daa47df31a to the source code tree and rebuild MP4Box on systems that do not require media-processing capabilities to reduce the attack surface.
  • Limit local user privileges so that only trusted accounts can execute MP4Box with potentially untrusted input, thereby reducing the opportunity for a local attacker to exploit the vulnerability.

Generated by OpenCVE AI on September 15, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded.
Title GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:23.385Z

Reserved: 2026-09-12T16:34:10.576Z

Link: CVE-2026-90577

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:26.370Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:53.183

Modified: 2026-09-15T15:17:28.817

Link: CVE-2026-90577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow