CVE-2026-91088: GPAC URL url.c gf_url_concatenate_ex heap-based overflow
A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gfurlconcatenateex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPACto a version that resolves this vulnerability.Fixed in abi-16.23Patch afca1f1181668d85941d51ed1adf647807d5d975 - Compensating control
Approach the attack locally (as stated: "An attack has to be approached locally") to limit exposure.
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running GPAC versions up to commit f1219cde are affected. Exploitation must be approached locally and requires low privileges plus user interaction, so remote-only exposure is not indicated by the available data.
What does an attacker need to exploit it?
An attacker needs local access, low-level privileges, and user interaction. The vulnerable code is the URL Handler's gf_url_concatenate_ex function in utils/url.c.
What is the recommended remediation?
Upgrade GPAC to version abi-16.23, which addresses the issue. The associated patch identifier is afca1f1181668d85941d51ed1adf647807d5d975.