Junglewise Threat Intelligence

CVE-2026-90610: GPAC buffer over-read in SVG attributes copy

CVE-2026-90610 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is a multimedia framework used for video streaming and media transcoding. MP4Box, a component of GPAC, contains a buffer over-read vulnerability in its SVG attribute handling that could allow a local attacker with access to craft malicious files to read sensitive data from memory or cause application crashes.

Technical details

A buffer over-read vulnerability exists in the gf_svg_attributes_copy function within scenegraph/svg_attributes.c of the MP4Box component. The vulnerability allows an attacker to read beyond allocated buffer boundaries when processing SVG attributes. This requires local access and a crafted input file. The vulnerability was patched in commit afca1f1181668d85941d51ed1adf647807d5d975 and is fixed in version abi-16.23 and later.

Affected products

  • GPAC GPAC up to f1219cde

Timeline

  • 2026-09-14: disclosed: Vulnerability published
  • 2026-07-27: patched: Patch commit afca1f1181668d85941d51ed1adf647807d5d975

References

Related threats