Impact
A memory corruption flaw exists in the gf_node_list_insert_child function of GPAC's scenegraph module. The bug is a classic buffer overflow (CWE‑119) that corrupts internal memory structures when node insertion is performed. The vulnerability can be triggered remotely through untrusted media inputs or network‑exposed file processing endpoints, and a publicly available exploit demonstrates that attackers can provoke the corruption without additional prerequisites.
Affected Systems
The affected vendor is GPAC. Every GPAC release up to commit f1219cde is impacted. The problem is fixed in the release tagged abi‑16.23, which includes patch 49dee5cad329cfed310c1682703df7daa47df31a.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so there are no documented widespread exploitation campaigns. Because exploitation can be performed remotely, any GPAC instance exposed to untrusted input streams remains at risk of receiving the memory corruption attack.
OpenCVE Enrichment