Description
A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use-after-free that can be triggered remotely, potentially leading to memory corruption and unpredictable behavior.
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the gf_node_changed_internal function of the GPAC MP4Box component. It results in a use‑after‑free condition that can be exploited from a remote source. Public disclosures indicate that attackers can leverage this flaw, though the exact outcomes (such as remote code execution) are not specified in the available data.

Affected Systems

GPAC users running GPAC MP4Box versions up to commit f1219cde are impacted. The issue is fixed in the abi-16.23 release, which applies the patch identified by commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the exploit is publicly available and can be initiated remotely, the risk of exploitation remains non‑negligible, especially in environments that use the affected GPAC component.

Generated by OpenCVE AI on September 15, 2026 at 15:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update GPAC to the abi-16.23 release, which includes the security patch for the use‑after‑free issue.
  • If upgrading is not immediately possible, apply the patch from commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24 directly to the source before rebuilding the component.
  • Continuously monitor GPAC release notes and security advisories for any future patches or additional mitigations related to the MP4Box component.

Generated by OpenCVE AI on September 15, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.
Title GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:01.836Z

Reserved: 2026-09-13T04:55:40.228Z

Link: CVE-2026-90687

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:26.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T06:16:58.677

Modified: 2026-09-15T14:17:28.237

Link: CVE-2026-90687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free