Junglewise Threat Intelligence

CVE-2026-90825: GPAC MP4Box use-after-free in gf_node_unregister

CVE-2026-90825 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is a multimedia framework and toolset used for processing, packaging, and delivering video and multimedia content. A use-after-free vulnerability in the MP4Box component could allow a local attacker to crash the application or potentially execute arbitrary code if malicious files are processed.

Technical details

A use-after-free vulnerability exists in the gf_node_unregister function within scenegraph/base_scenegraph.c of GPAC's MP4Box component. The vulnerability is triggered through the manipulation of scene graph node objects, allowing access to memory that has been previously freed. Local access is required to exploit this vulnerability. An attacker with local access can craft malicious input to trigger the flaw, potentially leading to information disclosure, denial of service, or code execution. A patch is available in commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24, and upgrading to version abi-16.23 or later addresses the issue.

Affected products

  • GPAC GPAC 26.07.0

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: Patch commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24

References

Related threats