Description
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Apply Patch
AI Analysis

Impact

A memory corruption flaw exists in the gf_node_list_insert_child function of GPAC's scenegraph module. The bug is a classic buffer overflow (CWE‑119) that corrupts internal memory structures when node insertion is performed. The vulnerability can be triggered remotely through untrusted media inputs or network‑exposed file processing endpoints, and a publicly available exploit demonstrates that attackers can provoke the corruption without additional prerequisites.

Affected Systems

The affected vendor is GPAC. Every GPAC release up to commit f1219cde is impacted. The problem is fixed in the release tagged abi‑16.23, which includes patch 49dee5cad329cfed310c1682703df7daa47df31a.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so there are no documented widespread exploitation campaigns. Because exploitation can be performed remotely, any GPAC instance exposed to untrusted input streams remains at risk of receiving the memory corruption attack.

Generated by OpenCVE AI on September 16, 2026 at 06:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to the abi‑16.23 release or later, which contains patch 49dee5cad329cfed310c1682703df7daa47df31a.
  • If an immediate upgrade is not possible, restrict GPAC from processing untrusted media or disable remote media ingestion features that invoke gf_node_list_insert_child.
  • Apply input validation or bounds checking at the point of node insertion, following guidelines for mitigating buffer overflows (CWE‑119) to ensure that buffer lengths are enforced.

Generated by OpenCVE AI on September 16, 2026 at 06:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
Title GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruption
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:19:26.571Z

Reserved: 2026-09-14T18:00:05.879Z

Link: CVE-2026-91091

cve-icon Vulnrichment

Updated: 2026-09-15T14:19:23.958Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T08:17:07.000

Modified: 2026-09-15T15:17:31.763

Link: CVE-2026-91091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T06:45:19Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer