Junglewise Threat Intelligence

CVE-2026-90611: GPAC MP4Box reachable assertion in XMT parsing

CVE-2026-90611 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used for video streaming and media transcoding. A vulnerability in the MP4Box component's XMT file parsing can trigger an assertion failure, potentially crashing the application during processing of specially crafted media files. This issue requires local execution and does not directly compromise data or authentication.

Technical details

The vulnerability is a reachable assertion triggered in the xmt_parse_element function of scene_manager/loader_xmt.c within the MP4Box component. The flaw arises from improper handling of malformed XMT (GPAC's XML-based scene format) input, allowing an attacker to trigger a controlled crash via a crafted file. Attack requires local execution of the affected parsing code. The issue does not permit code execution or privilege escalation, but causes denial of service through application termination. A patch was committed in July 2026 (commit afca1f1) and is included in version abi-16.23 and later.

Affected products

  • GPAC MP4Box up to f1219cde

Timeline

  • 2026-09-14: disclosed: CVE-2026-90611 published
  • 2026-07-27: patched: Fix committed (afca1f1); included in version abi-16.23

References

Related threats