Junglewise Threat Intelligence

CVE-2026-90612: GPAC MP4Box reachable assertion in scene_dump

CVE-2026-90612 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used for video streaming, transcoding, and packaging. MP4Box, a component of GPAC, contains a vulnerability in scene dump functionality that can be triggered by a specially crafted local input, causing an assertion failure that could lead to a denial of service.

Technical details

The vulnerability is a reachable assertion in the gf_sm_dump_command_list function within the scene_manager/scene_dump.c file of GPAC's MP4Box component. The flaw can be triggered through local manipulation of scene dump processing, affecting versions up to f1219cde. This is not a memory corruption issue but rather a logic error that triggers an assertion check. The attack requires local access and does not require elevated privileges. The issue was patched in commit afca1f1181668d85941d51ed1adf647807d5d975 included in version abi-16.23.

Affected products

  • GPAC GPAC up to f1219cde

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: Patch commit afca1f1181668d85941d51ed1adf647807d5d975

References

Related threats