Description
A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from a use‑after‑free in the gf_node_get_name_and_id function located in scenegraph/base_scenegraph.c. The flaw (CWE‑416) allows an attacker to read or write memory after it has been freed, potentially enabling arbitrary code execution or data leakage (CWE‑119). Because the function can be invoked remotely, a malicious actor can supply crafted input to trigger the freed memory usage, leading to compromise of confidentiality, integrity, or availability.

Affected Systems

The issue affects GPAC releases up to commit f1219cde, including any distribution before the abi‑16.23 tag. Users running the open‑source GPAC library without applying the 49dee5cad329cfed310c1682703df7daa47df31a patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the moment. The exploit is publicly available and can be triggered remotely, so attackers could target sensitive deployments. It is not listed in the CISA KEV catalog, but the public nature of the exploit and remote trigger elevate the risk relative to the low EPSS score.

Generated by OpenCVE AI on September 17, 2026 at 18:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to version abi‑16.23 or later to apply the 49dee5cad329cfed310c1682703df7daa47df31a patch.
  • If an immediate upgrade is not possible, isolate or quarantine environments that consume GPAC functionality to reduce exposure.
  • Restrict network access to GPAC‑enabled services, limiting connections to trusted hosts and VPNs to reduce the attack surface.

Generated by OpenCVE AI on September 17, 2026 at 18:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Title GPAC base_scenegraph.c gf_node_get_name_and_id use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:36:04.403Z

Reserved: 2026-09-14T17:59:58.113Z

Link: CVE-2026-91089

cve-icon Vulnrichment

Updated: 2026-09-15T17:35:59.129Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T08:17:06.617

Modified: 2026-09-15T18:19:38.653

Link: CVE-2026-91089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free