CVE-2026-90791: GPAC MP4Box base_scenegraph.c gf_node_unregister use after free
A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gfnodeunregister of the file scenegraph/basescenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to resolve this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC/MP4Boxto a version that resolves this vulnerability.Fixed in abi-16.23Patch 9eb40df4448b88d6a6ce3454657c06f47eff0b24
Event History
Frequently Asked Questions
Which GPAC MP4Box versions are affected and what version fixes the issue?
GPAC is affected through revision f1219cde. Upgrade to version abi-16.23, which includes the identified fix patch 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
Can this be exploited remotely, and is exploit code available?
Yes. The attack can be executed remotely, and a public exploit is reported to be available.