Junglewise Threat Intelligence

CVE-2026-90827: GPAC MP4Box use-after-free in gf_node_deactivate_ex

CVE-2026-90827 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used for video streaming and transcoding. A use-after-free vulnerability in the MP4Box component (which processes multimedia files) could allow a local attacker to crash the application or potentially execute code by providing a specially crafted media file.

Technical details

A use-after-free vulnerability exists in the gf_node_deactivate_ex function in scenegraph/base_scenegraph.c of GPAC's MP4Box component. The vulnerability is triggered through local file processing and requires no authentication or network access. An attacker can craft a malicious multimedia file to trigger the use-after-free condition, potentially leading to denial of service or code execution. The vulnerability has been patched in commit 49dee5cad329cfed310c1682703df7daa47df31a, and users should upgrade to version abi-16.23 or later.

Affected products

  • GPAC MP4Box 26.07.0

Timeline

  • 2026-09-14: disclosed
  • 2026-07-28: patched: Patch commit 49dee5cad329cfed310c1682703df7daa47df31a

References

Related threats