Junglewise Threat Intelligence

CVE-2026-90687: GPAC MP4Box use-after-free in gf_node_changed_internal

CVE-2026-90687 · Severity: medium · CVSS 6.3 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used for video streaming, transcoding, and packaging. The MP4Box component contains a use-after-free vulnerability that can be triggered when processing malformed scene graph files, leading to application crashes and potential heap memory corruption during cleanup operations.

Technical details

This vulnerability is a CWE-416 use-after-free flaw in the gf_node_replace() function within GPAC's scene graph handling code (scenegraph/base_scenegraph.c). The root cause is incorrect operation ordering: the function unregisters an old node before notifying the parent through gf_node_changed(), which causes the node and related prototype state to be freed. The subsequent parent notification traverses freed memory in gf_node_changed_internal(), triggering a heap-use-after-free read. The vulnerability is reachable through normal MP4Box -add file processing of untrusted scene description files, requiring no authentication or user interaction beyond file processing. An attacker can craft a malformed scene file to trigger the defect, causing MP4Box to crash during cleanup and potentially achieving heap memory corruption. The upstream fix (commit 9eb40df4) reorders operations to notify the parent before unregistering, ensuring the node remains valid during traversal. Upgrade to GPAC version abi-16.23 or apply patch 9eb40df4448b88d6a6ce3454657c06f47eff0b24.

Affected products

  • GPAC GPAC up to commit f1219cde

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: Upstream fix commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24
  • 2026-07-27: other: Publicly disclosed

References

Related threats