Denial of Service Vulnerability in GPAC MP4Box Component
CVE-2026-90683
Key Information:
Badges
What is CVE-2026-90683?
A vulnerability exists in the GPAC MP4Box component, specifically in the gf_node_unregister function within scenegraph/base_scenegraph.c. This issue can be exploited through local manipulation, leading to a reachable assertion failure. Attackers may utilize public exploits to trigger this vulnerability. Users are strongly advised to upgrade to version abi-16.23 to mitigate the risk associated with this vulnerability. Note that this issue is distinct from previous vulnerabilities identified as CVE-2021-46237 and CVE-2021-46234.
Affected Version(s)
GPAC f1219cde
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
