CVE-2026-91090: GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow
A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gfnodeactivateex of the file scenegraph/basescenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPACto a version that resolves this vulnerability.Fixed in abi-16.23Patch 9eb40df4448b88d6a6ce3454657c06f47eff0b24
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
The attack is described as local-host only. Exploitation requires local access and low privileges, along with user interaction.
Is public exploit code available?
Yes. The exploit has been publicly disclosed and may be used.
What version fixes the issue?
Upgrade GPAC to version abi-16.23. The identified patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
How can I determine whether an installation is affected?
Installations of GPAC at or before revision f1219cde are affected according to the available information. Verify the installed version or source revision and confirm whether the listed patch or abi-16.23 upgrade is present.