Junglewise Threat Intelligence

CVE-2026-91087: GPAC use-after-free in media object compositor

CVE-2026-91087 · Severity: high · CVSS 7.3 · Published 2026-09-15

Executive brief

GPAC is a multimedia framework used for video streaming and media transcoding. A use-after-free vulnerability in the media object compositor component could allow remote attackers to cause crashes or potentially execute arbitrary code by sending specially crafted multimedia content.

Technical details

A use-after-free vulnerability exists in the gf_mo_get_od_id function within compositor/media_object.c of GPAC up to commit f1219cde. The vulnerability can be triggered remotely without authentication by providing malicious input to the compositor component. An attacker can exploit this flaw to read or write memory after it has been freed, potentially leading to information disclosure or code execution. The issue was patched in commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7 (included in version abi-16.24).

Affected products

  • GPAC Project GPAC up to f1219cde (before abi-16.24)

Timeline

  • 2026-09-15: disclosed: CVE-2026-91087 disclosed
  • 2026-08-03: patched: Fix published in commit e34f4ba, included in version abi-16.24

References