Description
A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 can resolve this issue. The name of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote heap‑based buffer overflow
Action: Apply patch
AI Analysis

Impact

The vulnerability originates in the mpgviddmx_process function of GPAC's MPEG Video Reframer component, where malformed MPEG‑video streams trigger a heap‑based buffer overflow. This flaw is a classic buffer overflow (CWE‑119/122) that can be exploited remotely, potentially allowing memory corruption, arbitrary code execution, or denial of service.

Affected Systems

GPAC is affected in all releases older than commit f1219cde. Versions prior to abi‑16.23 contain the flaw, while the patch commit afca1f1181668d85941d51ed1adf647807d5d975 is incorporated in release abi‑16.23 and later, resolving the issue.

Risk and Exploitability

The EPSS score of <1% indicates that exploitation is currently very unlikely, and the vulnerability is not listed in the CISA KEV catalog. A public exploit has been disclosed and the flaw is remotely triggerable by delivering malicious MPEG video through the affected component. The CVSS score of 5.3 reflects moderate severity; if exploited, an attacker could gain code execution or crash the application. Because the vulnerability can be triggered without local privileges, administrators should consider remediation priority low to medium, depending on the exposure of the affected component.

Generated by OpenCVE AI on September 17, 2026 at 18:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to release abi‑16.23 or later, which contains the fixed code.
  • If upgrading is not immediately possible, apply the patch identified by commit afca1f1181668d85941d51ed1adf647807d5d975 to the MPEG Video Reframer component.
  • Limit or block the delivery of arbitrary MPEG video streams to the GPAC instance until the update is applied, and monitor for anomalous application crashes or memory corruption events.

Generated by OpenCVE AI on September 17, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 can resolve this issue. The name of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.
Title GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflow
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:16:02.760Z

Reserved: 2026-09-14T17:59:47.294Z

Link: CVE-2026-91086

cve-icon Vulnrichment

Updated: 2026-09-15T14:15:58.794Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T07:16:34.050

Modified: 2026-09-15T15:17:31.470

Link: CVE-2026-91086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow