Description
A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is recommended to address this issue. The name of the patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use After Free
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free bug resides in the GPAC MP4Box component in the gf_node_get_name function of scenegraph/base_scenegraph.c. Attackers can trigger memory corruption by sending specially crafted MP4 files to the affected process. The vulnerability can crash the program and, under certain circumstances, may lead to arbitrary code execution or compromise of the host system, given that the defect resides in a core media handling library.

Affected Systems

The issue affects any installation of GPAC up to commit f1219cde, which includes all versions prior to abi-16.23. Versions newer than abi-16.23 contain the patch from commit 9eb40df4, thereby eliminating the flaw. The affected product is the GPAC MP4Box media utilities, bundled with the GPAC CVSS score of 5.3 indicates a moderate severity, and the EPSS score is currently unavailable, so the exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog yet, but the existence of a publicly disclosed exploit means the risk is real. Attackers can target the application from remote, typically by delivering malicious MP4 content, which triggers the use‑after‑free. Once triggered, the defect may allow memory corruption leading to a crash or, potentially, end‑to‑end control over the process, depending on the underlying system configuration and the privileges of the executing user.

Risk and Exploitability

The flaw is a classic use‑after‑free (CWE-416). An attacker may exploit this by crafting a malicious MP4 file that triggers gf_node_get_name vulnerability is delivered through supplied media content, the attack vector is remote – the attacker can send the file over a network interface or embed it in a location accessed by the target system. The CVSS score of 5.3 indicates moderate severity, the EPSS score is not available, and it is not listed in the CISA KEV catalog; nevertheless, the public availability of an exploit suggests that the probability of real‑world exploitation exists, especially for systems that expose MP4Box or a similar media parsing service to untrusted input.

Generated by OpenCVE AI on September 15, 2026 at 13:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to at least version abi-16.23 or later; this releases the patch commit 9eb40df4.
  • After updating, validate that MP4Box processes benign files without failures and that the application remains functional in your environment.
  • If an upgrade cannot be performed immediately, limit the processing of MP4 files to trusted sources, disable any network exposure of the MP4Box service, and isolate the instance from untrusted input to reduce the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is recommended to address this issue. The name of the patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.
Title GPAC MP4Box base_scenegraph.c gf_node_get_name use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:10:29.004Z

Reserved: 2026-09-13T13:37:07.849Z

Link: CVE-2026-90793

cve-icon Vulnrichment

Updated: 2026-09-16T15:10:24.515Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:41.093

Modified: 2026-09-16T16:17:20.853

Link: CVE-2026-90793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free