Description
A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version abi-16.23 is capable of addressing this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference occurs in the gf_node_list_get_child function of GPAC's MP4Box when the Target argument is manipulated. This flaw causes the application to crash, which can be triggered by an attacker supplying crafted input over a network. The vulnerability is classified as a memory management error (CWE‑476) and an unchecked return value issue (CWE‑404).

Affected Systems

All released versions of GPAC up to commit f1219cde, including the MP4Box component on any operating system where it is executed, are affected. The known fix is version abi‑16.23 or the patch commit afca1f1181668d85941d51ed1adf647807d5d975. If the environment runs older GPAC binaries or uses MP4Box as a server‑side tool, the vulnerability is present.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. Nevertheless, the threat is real because a public exploit exists and the attack vector is remote with no authentication required. The impact is limited to application denial of service, which could disrupt processing pipelines or media servers but does not grant code execution or data disclosure. This vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 14:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit afca1f1181668d85941d51ed1adf647807d5d975 or upgrade to GPAC abi‑16.23.
  • Limit exposure of the MP4Box executable to trusted inputs, for example by restricting network access or running it in an isolated environment.
  • Monitor logs and system metrics for unexpected crashes or abnormal input patterns and configure alerts for such events.

Generated by OpenCVE AI on September 15, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version abi-16.23 is capable of addressing this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.
Title GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T16:48:32.019Z

Reserved: 2026-09-13T13:37:04.438Z

Link: CVE-2026-90792

cve-icon Vulnrichment

Updated: 2026-09-14T16:48:25.800Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:40.907

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference