CVE-2026-91089: GPAC base_scenegraph.c gf_node_get_name_and_id use after free
A vulnerability was found in GPAC up to f1219cde. Impacted is the function gfnodegetnameandid of the file scenegraph/basescenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPACto a version that resolves this vulnerability.Fixed in abi-16.23Patch 49dee5cad329cfed310c1682703df7daa47df31a
Event History
Frequently Asked Questions
What is the recommended fixed version and patch identifier?
Upgrade GPAC to version abi-16.23. The identified patch is 49dee5cad329cfed310c1682703df7daa47df31a.
Can this be exploited remotely without prior privileges?
Yes. The issue can be launched remotely, and the supplied vector indicates network attack access with no privileges required, although user interaction is required.
Is public exploit information available?
Yes. The exploit has been made public and could be used.