Description
A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.
Published: 2026-09-15
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Heap Buffer Overflow
Action: Patch
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in the gf_url_concatenate_ex function of GPAC's URL handler (utils/url.c). An attacker could provide crafted inputs to overflow a buffering memory and causing crashes or malicious code execution. The weakness falls under CWE-119 (Improper Input Validation-based Buffer Overflow).

Affected Systems

121 The fix is available in release abi-16.23, which incorporates the patch with commit afca1f1181668d85941d51ed1adf647807d5d975. Only the GPAC product from vendor GPAC is impacted.

Risk and Exploitability

The CVSS score is 2.4, indicating low severity, and the EPSS score is less than 1%, reflecting a very low probability of exploitation. The vulnerability requires local execution, and it is not listed in the CISA KEV catalog. Because local access is required, the threat to an organization is limited to environments where users can run GPAC or where GPAC is exposed to untrusted data on a local machine.

Generated by OpenCVE AI on September 17, 2026 at 18:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi-16.23 or later, which incorporates the inexpensive patch to gf_url_concatenate_ex.
  • If you compile from source, apply commit afca1f1181668d85941d51ed1adf647807d5d975 to your code base before building.
  • Restrict local execution of GPAC to trusted users or processes to minimize the risk of local exploitation.

Generated by OpenCVE AI on September 17, 2026 at 18:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.
Title GPAC URL url.c gf_url_concatenate_ex heap-based overflow
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:46:48.677Z

Reserved: 2026-09-14T17:59:54.939Z

Link: CVE-2026-91088

cve-icon Vulnrichment

Updated: 2026-09-15T14:46:25.337Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T07:16:34.423

Modified: 2026-09-15T15:17:31.613

Link: CVE-2026-91088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow