Memory Corruption Vulnerability in GPAC by GPAC
CVE-2026-91091
Key Information:
Badges
What is CVE-2026-91091?
A vulnerability affecting GPAC prior to version abi-16.23 has been identified in the Node Insertion component, specifically within the gf_node_list_insert_child function in the base_scenegraph.c file. This vulnerability can lead to memory corruption, allowing remote exploitation of the affected software. It is critical for users to take necessary actions to upgrade to the patched version to secure their systems against potential remote attacks, as public exploits are available.
Affected Version(s)
GPAC f1219cde
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
