Description
A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.
Published: 2026-09-15
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stack-based buffer overflow, potential memory corruption
Action: Patch Upgrade
AI Analysis

Impact

The vulnerability in GPAC's gf_node_activate_ex function allows an attacker to trigger a stack-based buffer overflow through crafted media content. The overflow corrupts the stack frame, potentially leading to memory corruption or a program crash. Because the flaw is local only, an attacker requires access to the system where GPAC processes media, and can exploit via locally crafted files or over a local network. integrity, and availability for the process. While the buffer overflow does not grant remote code execution, it can be used to crash the application or facilitate further escalation if additional vulnerabilities exist.

Affected Systems

GPAC, the open-source media framework, is affected. All versions up to commit f1219cde are vulnerable. The fix is available in release abi‑16.23, applied in commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24.

Risk and Exploitability

The CVSS score of 2.4 indicates low severity, and the exploitation probability is very low. The vulnerability is not listed in CISA KEV, so no known large scale attacks are reported. The flaw requires local execution, so exploitation depends on an attacker already having access to the target host and the ability to exploit demonstrates that the overflow can exploit or privileged escalation is known at this time.

Generated by OpenCVE AI on September 17, 2026 at 18:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to release abi‑16.23 or later, which includes the fixed commit.
  • Run any processes that load untrusted media with the lowest privileges or within a sandboxed environment to limit the impact of a potential crash or memory corruption.
  • Monitor system logs for crash events or abnormal behavior that may indicate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.
Title GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 3.2, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.9, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T13:59:51.515Z

Reserved: 2026-09-14T18:00:01.604Z

Link: CVE-2026-91090

cve-icon Vulnrichment

Updated: 2026-09-17T13:59:47.421Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T08:17:06.807

Modified: 2026-09-17T14:17:53.157

Link: CVE-2026-91090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow