Junglewise Threat Intelligence

CVE-2026-90683: GPAC gf_node_unregister reachable assertion in MP4Box

CVE-2026-90683 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is multimedia software used for video streaming and transcoding. MP4Box is its utility for processing media files. A flaw in the gf_node_unregister function can trigger an assertion failure when processing malformed input, crashing the application. This requires local access and could disrupt video processing workflows.

Technical details

This is a reachable assertion vulnerability in the gf_node_unregister function within scenegraph/base_scenegraph.c of GPAC's MP4Box component. The vulnerability is triggered by manipulating input data that causes an assertion to fail, resulting in denial of service via application crash. Attack requires local system access and the ability to provide crafted input to the MP4Box utility. The patch is available in commit 49dee5cad329cfed310c1682703df7daa47df31a and shipping with GPAC version abi-16.23 or later.

Affected products

  • GPAC GPAC up to f1219cde

Timeline

  • 2026-09-14: disclosed
  • 2026-07-28: patched: patch commit 49dee5cad329cfed310c1682703df7daa47df31a; fixed in version abi-16.23

References

Related threats