Heap-Based Buffer Overflow in GPAC's URL Handler Function
CVE-2026-91088

2.4LOW

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91088?

A vulnerability exists in the GPAC media framework affecting the URL Handler component. Specifically, the gf_url_concatenate_ex function contains a flaw that can lead to a heap-based buffer overflow. This vulnerability requires local access to exploit effectively, which could allow attackers to manipulate memory, potentially resulting in code execution or denial of service. Users are advised to upgrade to version abi-16.23 or later, which includes a patch to mitigate this vulnerability. The fix is documented with the identifier afca1f1181668d85941d51ed1adf647807d5d975.

Affected Version(s)

GPAC f1219cde

GPAC abi-16.23

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wsstssw (VulDB User)
.