Executive brief
GPAC is an open-source multimedia framework used for video streaming and media transcoding. A vulnerability in the MP4Box component's XMT file parsing can trigger an assertion failure, potentially crashing the application during processing of specially crafted media files. This issue requires local execution and does not directly compromise data or authentication.
Technical details
The vulnerability is a reachable assertion triggered in the xmt_parse_element function of scene_manager/loader_xmt.c within the MP4Box component. The flaw arises from improper handling of malformed XMT (GPAC's XML-based scene format) input, allowing an attacker to trigger a controlled crash via a crafted file. Attack requires local execution of the affected parsing code. The issue does not permit code execution or privilege escalation, but causes denial of service through application termination. A patch was committed in July 2026 (commit afca1f1) and is included in version abi-16.23 and later.
Affected products
- GPAC MP4Box up to f1219cde
Timeline
- 2026-09-14: disclosed: CVE-2026-90611 published
- 2026-07-27: patched: Fix committed (afca1f1); included in version abi-16.23