Junglewise Threat Intelligence

CVE-2026-90609: GPAC null pointer dereference in MP4Box

CVE-2026-90609 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia toolkit used for video processing and transcoding. A null pointer dereference vulnerability in the MP4Box component allows a local attacker with access to craft malicious media files to crash the application, causing denial of service.

Technical details

The vulnerability is a null pointer dereference (CWE-476) in an unknown function within scenegraph/vrml_tools.c of the MP4Box component. The defect arises from insufficient null-pointer validation in VRML scene graph processing. Attack requires local file system access to provide a specially crafted input file to the application. Successful exploitation results in application crash and denial of service. The vulnerability was patched in commit 49dee5cad329cfed310c1682703df7daa47df31a, available in version abi-16.23 or later.

Affected products

  • GPAC GPAC up to f1219cde

Timeline

  • 2026-09-14: disclosed
  • 2026-07-28: patched: Fix available in commit 49dee5cad329cfed310c1682703df7daa47df31a and version abi-16.23

References

Related threats