Description
A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Published: 2026-09-14
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Local)
Action: Immediate Patch
AI Analysis

Impact

The flaw exists in the gf_node_get_field_count function of the GPAC attacker can craft input that causes the function to trigger an assertion failure, terminating the process. This results in a local denial of service because the program crashes and is an unchecked input handling flaw identified by CWE-617.

Affected Systems

Affected products are the GPAC software suite, specifically the MP4Box component, in all releases up to the commit identifier f1219cde. The security fix is available in version abi-16.23, which incorporates the patch identified by commit 49dee5cad329cfed310c1682703df7daa47df31a. Devices or systems running earlier versions are vulnerable.

Risk and Exploitability

The CVSS score of 2.4 indicates low severity. The EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA KEV. An attacker with local access can trigger the assertion by supplying crafted input to gf_node_get_field_count, causing a crash and local denial of service. No escalation or data compromise occurs.

Generated by OpenCVE AI on September 15, 2026 at 15:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi-16.23 which includes the security fix
  • Apply the patch corresponding to commit 49dee5cad329cfed310c1682703df7daa47df31a if your installation cannot be upgraded directly
  • Restrict the execution of MP4Box to non‑privileged users and validate all input to limit potential denial of service impact

Generated by OpenCVE AI on September 15, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Title GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-617
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 2.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:47:39.807Z

Reserved: 2026-09-13T04:55:28.502Z

Link: CVE-2026-90684

cve-icon Vulnrichment

Updated: 2026-09-14T15:47:24.123Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:59.067

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses