Heap-Based Buffer Overflow in GPAC MPEG Video Reframer by GPAC
CVE-2026-91086
Key Information:
Badges
What is CVE-2026-91086?
A security vulnerability has been identified in the MPEG Video Reframer function, specifically in the mpgviddmx_process of the filters/reframe_mpgvid.c file of GPAC up to version f1219cde. This vulnerability allows for heap-based buffer overflow, making it possible for attackers to execute remote exploits. The vulnerability has been publicly disclosed, and it is strongly advised to upgrade to version abi-16.23 to mitigate the risk. The corresponding patch is identified as afca1f1181668d85941d51ed1adf647807d5d975.
Affected Version(s)
GPAC f1219cde
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
