Description
A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

GF_NODE_UNREGISTER reaches an assertion in base_scenegraph.c, causing the GPAC MP4Box component to crash when an attacker manipulates input. This failure does not compromise confidentiality or integrity but disrupts functionality, which can be interpreted as a denial of service. The flaw stems from an unchecked return value leading to an unexpected assertion failure, classified as CWE‑617.

Affected Systems

GPAC, the multimedia framework that includes the MP4Box component, is vulnerable in all releases up to the commit f1219cde. Users running any of those versions can be affected. The official fix is available in version abi‑16.23, where the problematic assertion logic has been removed or protected.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity. Exploitation requires local access to the machine running GPAC, meaning only users or processes with write capabilities on the local system can trigger the assertion. No public exploit is listed in the CISA KEV catalog, and the EPSS score is < 1% (0.00118), indicating a low but non‑zero probability of exploitation. The threat is not actively exploited at a large scale.

Generated by OpenCVE AI on September 15, 2026 at 15:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to GPAC version abi‑16.23, which contains the fixed gf_node_unregister logic.
  • Restrict local access to applications that handle untrusted data, ensuring only authorized users can run or interact with MP4Box.
  • Implement monitoring for application crashes or abnormal restarts caused by local manipulation, and respond with an immediate security review.

Generated by OpenCVE AI on September 15, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234.
Title GPAC MP4Box base_scenegraph.c gf_node_unregister assertion
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-617
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:22:25.332Z

Reserved: 2026-09-13T04:55:25.133Z

Link: CVE-2026-90683

cve-icon Vulnrichment

Updated: 2026-09-15T17:21:15.777Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:58.900

Modified: 2026-09-15T18:19:37.977

Link: CVE-2026-90683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses