Junglewise Threat Intelligence

CVE-2026-90791: GPAC MP4Box use-after-free in gf_node_unregister

CVE-2026-90791 · Severity: medium · CVSS 6.3 · Published 2026-09-14

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework that includes MP4Box, a tool for processing multimedia files. A malformed XMT scene document can trigger a use-after-free memory error in MP4Box during file processing, causing the application to crash and resulting in a denial of service. In embedded implementations, this vulnerability could potentially allow memory corruption leading to more severe impact.

Technical details

A use-after-free vulnerability (CWE-416) exists in the gf_node_unregister function within GPAC's scenegraph component, affecting versions up to f1219cde. The root cause is improper handling of nested or prematurely terminated ProtoDeclare elements in XMT documents, which leaves stale prototype default-node references in the scene graph. During cleanup, these dangling pointers are dereferenced after the prototype subgraph has been freed. The vulnerability is triggered when processing crafted XMT files with malformed prototype declarations, and requires no authentication or user interaction beyond opening the malicious file. An attacker can achieve denial of service through application crash; in certain embedded contexts, heap reuse could enable further memory corruption. The fix (commit 9eb40df4) rejects nested prototype declarations and explicitly unregisters prototype default-node values before subgraph destruction.

Affected products

  • GPAC MP4Box up to f1219cde

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: Upstream fix commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24

References

Related threats