{"schema_version":1,"title":"GPAC vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 47 vulnerabilities in GPAC: 0 in the last 7 days and 42 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93331, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/gpac","json_url":"https://junglewise.ai/threats/technologies/gpac.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gpac","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":47,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":34,"last_90_days":42,"last_365_days":47},"latest":[{"cve":"CVE-2026-93331","cvss":7.3,"epss":0.0054,"slug":"cve-2026-93331-gpac-out-of-bounds-read-in-rtp-depacketizer","title":"GPAC out-of-bounds read in RTP depacketizer","severity":"high","exploited":false,"published_at":"2026-09-18T02:17:08.78+00:00","url":"https://junglewise.ai/threats/cve-2026-93331-gpac-out-of-bounds-read-in-rtp-depacketizer"},{"cve":"CVE-2026-92475","cvss":5.3,"epss":0.0016,"slug":"cve-2026-92475-gpac-out-of-bounds-read-in-downloader-content-range-handling","title":"GPAC out-of-bounds read in downloader Content-Range handling","severity":"medium","exploited":false,"published_at":"2026-09-16T20:17:48.78+00:00","url":"https://junglewise.ai/threats/cve-2026-92475-gpac-out-of-bounds-read-in-downloader-content-range-handling"},{"cve":"CVE-2026-92474","cvss":3.3,"epss":0.0017,"slug":"cve-2026-92474-gpac-use-after-free-in-proto-link-handler","title":"GPAC use-after-free in Proto Link Handler","severity":"low","exploited":false,"published_at":"2026-09-16T20:17:48.61+00:00","url":"https://junglewise.ai/threats/cve-2026-92474-gpac-use-after-free-in-proto-link-handler"},{"cve":"CVE-2026-92473","cvss":3.3,"epss":0.0017,"slug":"cve-2026-92473-gpac-use-after-free-in-bifs-handler","title":"GPAC use after free in BIFS Handler","severity":"low","exploited":false,"published_at":"2026-09-16T19:18:06.583+00:00","url":"https://junglewise.ai/threats/cve-2026-92473-gpac-use-after-free-in-bifs-handler"},{"cve":"CVE-2026-92472","cvss":3.3,"epss":0.0017,"slug":"cve-2026-92472-gpac-use-after-free-in-gf-node-deactivate-ex","title":"GPAC use-after-free in gf_node_deactivate_ex","severity":"low","exploited":false,"published_at":"2026-09-16T19:18:06.377+00:00","url":"https://junglewise.ai/threats/cve-2026-92472-gpac-use-after-free-in-gf-node-deactivate-ex"},{"cve":"CVE-2026-92399","cvss":7.3,"epss":0.0069,"slug":"cve-2026-92399-gpac-heap-based-buffer-overflow-in-websocket-handler","title":"GPAC heap-based buffer overflow in WebSocket handler","severity":"high","exploited":false,"published_at":"2026-09-16T17:18:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-92399-gpac-heap-based-buffer-overflow-in-websocket-handler"},{"cve":"CVE-2026-91091","cvss":4.3,"epss":0.0069,"slug":"cve-2026-91091-gpac-memory-corruption-in-node-insertion","title":"GPAC memory corruption in node insertion","severity":"medium","exploited":false,"published_at":"2026-09-15T08:17:07+00:00","url":"https://junglewise.ai/threats/cve-2026-91091-gpac-memory-corruption-in-node-insertion"},{"cve":"CVE-2026-91090","cvss":3.9,"epss":0.0017,"slug":"cve-2026-91090-gpac-stack-based-buffer-overflow-in-scenegraph-base-module","title":"GPAC stack-based buffer overflow in scenegraph base module","severity":"low","exploited":false,"published_at":"2026-09-15T08:17:06.807+00:00","url":"https://junglewise.ai/threats/cve-2026-91090-gpac-stack-based-buffer-overflow-in-scenegraph-base-module"},{"cve":"CVE-2026-91089","cvss":6.3,"epss":0.0051,"slug":"cve-2026-91089-gpac-use-after-free-in-gf-node-get-name-and-id","title":"GPAC use after free in gf_node_get_name_and_id","severity":"medium","exploited":false,"published_at":"2026-09-15T08:17:06.617+00:00","url":"https://junglewise.ai/threats/cve-2026-91089-gpac-use-after-free-in-gf-node-get-name-and-id"},{"cve":"CVE-2026-91088","cvss":4.8,"epss":0.0016,"slug":"cve-2026-91088-gpac-heap-based-buffer-overflow-in-url-handler","title":"GPAC heap-based buffer overflow in URL handler","severity":"medium","exploited":false,"published_at":"2026-09-15T07:16:34.423+00:00","url":"https://junglewise.ai/threats/cve-2026-91088-gpac-heap-based-buffer-overflow-in-url-handler"},{"cve":"CVE-2026-91087","cvss":7.3,"epss":0.0064,"slug":"cve-2026-91087-gpac-use-after-free-in-media-object-compositor","title":"GPAC use-after-free in media object compositor","severity":"high","exploited":false,"published_at":"2026-09-15T07:16:34.237+00:00","url":"https://junglewise.ai/threats/cve-2026-91087-gpac-use-after-free-in-media-object-compositor"},{"cve":"CVE-2026-91086","cvss":6.3,"epss":0.0055,"slug":"cve-2026-91086-gpac-heap-based-buffer-overflow-in-mpeg-video-reframer","title":"GPAC heap-based buffer overflow in MPEG Video Reframer","severity":"medium","exploited":false,"published_at":"2026-09-15T07:16:34.05+00:00","url":"https://junglewise.ai/threats/cve-2026-91086-gpac-heap-based-buffer-overflow-in-mpeg-video-reframer"},{"cve":"CVE-2026-90825","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90825-gpac-mp4box-use-after-free-in-gf-node-unregister","title":"GPAC MP4Box use-after-free in gf_node_unregister","severity":"low","exploited":false,"published_at":"2026-09-14T22:16:58.1+00:00","url":"https://junglewise.ai/threats/cve-2026-90825-gpac-mp4box-use-after-free-in-gf-node-unregister"},{"cve":"CVE-2026-90824","cvss":3.3,"epss":0.0018,"slug":"cve-2026-90824-gpac-stack-based-buffer-overflow-in-dom-event-handling","title":"GPAC stack-based buffer overflow in DOM event handling","severity":"low","exploited":false,"published_at":"2026-09-14T21:17:42.55+00:00","url":"https://junglewise.ai/threats/cve-2026-90824-gpac-stack-based-buffer-overflow-in-dom-event-handling"},{"cve":"CVE-2026-90793","cvss":5.4,"epss":0.0058,"slug":"cve-2026-90793-gpac-mp4box-heap-use-after-free-in-gf-node-get-name","title":"GPAC MP4Box heap use-after-free in gf_node_get_name","severity":"medium","exploited":false,"published_at":"2026-09-14T16:17:41.093+00:00","url":"https://junglewise.ai/threats/cve-2026-90793-gpac-mp4box-heap-use-after-free-in-gf-node-get-name"},{"cve":"CVE-2026-90792","cvss":4.3,"epss":0.0069,"slug":"cve-2026-90792-gpac-mp4box-null-pointer-dereference-in-gf-node-list-get-child","title":"GPAC MP4Box null pointer dereference in gf_node_list_get_child","severity":"medium","exploited":false,"published_at":"2026-09-14T16:17:40.907+00:00","url":"https://junglewise.ai/threats/cve-2026-90792-gpac-mp4box-null-pointer-dereference-in-gf-node-list-get-child"},{"cve":"CVE-2026-90687","cvss":6.3,"epss":0.0051,"slug":"cve-2026-90687-gpac-mp4box-use-after-free-in-gf-node-changed-internal","title":"GPAC MP4Box use-after-free in gf_node_changed_internal","severity":"medium","exploited":false,"published_at":"2026-09-14T06:16:58.677+00:00","url":"https://junglewise.ai/threats/cve-2026-90687-gpac-mp4box-use-after-free-in-gf-node-changed-internal"},{"cve":"CVE-2026-90685","cvss":2.8,"epss":0.0016,"slug":"cve-2026-90685-gpac-mp4box-reachable-assertion-in-lsr-command-processing","title":"GPAC MP4Box reachable assertion in LSR command processing","severity":"low","exploited":false,"published_at":"2026-09-14T06:16:58.3+00:00","url":"https://junglewise.ai/threats/cve-2026-90685-gpac-mp4box-reachable-assertion-in-lsr-command-processing"},{"cve":"CVE-2026-90684","cvss":2.8,"epss":0.0016,"slug":"cve-2026-90684-gpac-mp4box-reachable-assertion-in-gf-node-get-field-count","title":"GPAC MP4Box reachable assertion in gf_node_get_field_count","severity":"low","exploited":false,"published_at":"2026-09-14T05:16:59.067+00:00","url":"https://junglewise.ai/threats/cve-2026-90684-gpac-mp4box-reachable-assertion-in-gf-node-get-field-count"},{"cve":"CVE-2026-90683","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90683-gpac-gf-node-unregister-reachable-assertion-in-mp4box","title":"GPAC gf_node_unregister reachable assertion in MP4Box","severity":"low","exploited":false,"published_at":"2026-09-14T05:16:58.9+00:00","url":"https://junglewise.ai/threats/cve-2026-90683-gpac-gf-node-unregister-reachable-assertion-in-mp4box"},{"cve":"CVE-2026-90613","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90613-gpac-mp4box-assertion-failure-in-stbl-getsampleinfos","title":"GPAC MP4Box assertion failure in stbl_GetSampleInfos","severity":"low","exploited":false,"published_at":"2026-09-14T02:17:15.69+00:00","url":"https://junglewise.ai/threats/cve-2026-90613-gpac-mp4box-assertion-failure-in-stbl-getsampleinfos"},{"cve":"CVE-2026-90612","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90612-gpac-mp4box-reachable-assertion-in-scene-dump","title":"GPAC MP4Box reachable assertion in scene_dump","severity":"low","exploited":false,"published_at":"2026-09-14T02:17:15.533+00:00","url":"https://junglewise.ai/threats/cve-2026-90612-gpac-mp4box-reachable-assertion-in-scene-dump"},{"cve":"CVE-2026-90610","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90610-gpac-buffer-over-read-in-svg-attributes-copy","title":"GPAC buffer over-read in SVG attributes copy","severity":"low","exploited":false,"published_at":"2026-09-14T02:17:15.15+00:00","url":"https://junglewise.ai/threats/cve-2026-90610-gpac-buffer-over-read-in-svg-attributes-copy"},{"cve":"CVE-2026-90609","cvss":3.3,"epss":0.0017,"slug":"cve-2026-90609-gpac-null-pointer-dereference-in-mp4box","title":"GPAC null pointer dereference in MP4Box","severity":"low","exploited":false,"published_at":"2026-09-14T01:16:28.36+00:00","url":"https://junglewise.ai/threats/cve-2026-90609-gpac-null-pointer-dereference-in-mp4box"},{"cve":"CVE-2026-90577","cvss":5.3,"epss":0.0018,"slug":"cve-2026-90577-gpac-heap-buffer-overflow-in-scenegraph","title":"GPAC heap buffer overflow in scenegraph","severity":"medium","exploited":false,"published_at":"2026-09-13T19:16:53.183+00:00","url":"https://junglewise.ai/threats/cve-2026-90577-gpac-heap-buffer-overflow-in-scenegraph"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":24},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Gpac MP4Box","slug":"mp4box","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/mp4box"}],"technology":{"hub":true,"name":"GPAC","slug":"gpac","vendor":{"name":"Gpac","slug":"gpac","url":"https://junglewise.ai/threats/vendors/gpac"},"aliases":[],"category":"library","homepage":"https://gpac.io/","repo_url":"https://github.com/gpac/gpac","description":"GPAC is an open-source multimedia framework focused on modularity and standards compliance, widely used for packaging and streaming content.","url":"https://junglewise.ai/threats/technologies/gpac"},"most_severe":[{"cve":"CVE-2026-71614","cvss":8.4,"epss":0.0022,"slug":"cve-2026-71614-gpac-integer-underflow-in-dvb-mpe-c","title":"GPAC integer underflow in dvb_mpe.c","severity":"high","exploited":false,"published_at":"2026-09-09T20:20:21.87+00:00","url":"https://junglewise.ai/threats/cve-2026-71614-gpac-integer-underflow-in-dvb-mpe-c"},{"cve":"CVE-2026-71612","cvss":8.4,"epss":0.0021,"slug":"cve-2026-71612-gpac-buffer-overflow-in-nhntdmx-process-via-long-file-path","title":"GPAC buffer overflow in nhntdmx_process via long file path","severity":"high","exploited":false,"published_at":"2026-09-09T20:20:21.587+00:00","url":"https://junglewise.ai/threats/cve-2026-71612-gpac-buffer-overflow-in-nhntdmx-process-via-long-file-path"},{"cve":"CVE-2026-71613","cvss":7.8,"epss":0.002,"slug":"cve-2026-71613-gpac-buffer-overflow-in-j2kdec-process-jp2-decoder","title":"GPAC buffer overflow in j2kdec_process JP2 decoder","severity":"high","exploited":false,"published_at":"2026-09-09T20:20:21.747+00:00","url":"https://junglewise.ai/threats/cve-2026-71613-gpac-buffer-overflow-in-j2kdec-process-jp2-decoder"},{"cve":"CVE-2026-52489","cvss":7.8,"epss":0.0019,"slug":"cve-2026-52489-gpac-buffer-overflow-in-svg-name-handling","title":"GPAC buffer overflow in SVG name handling","severity":"high","exploited":false,"published_at":"2026-08-25T21:17:01.34+00:00","url":"https://junglewise.ai/threats/cve-2026-52489-gpac-buffer-overflow-in-svg-name-handling"},{"cve":"CVE-2026-92399","cvss":7.3,"epss":0.0069,"slug":"cve-2026-92399-gpac-heap-based-buffer-overflow-in-websocket-handler","title":"GPAC heap-based buffer overflow in WebSocket handler","severity":"high","exploited":false,"published_at":"2026-09-16T17:18:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-92399-gpac-heap-based-buffer-overflow-in-websocket-handler"},{"cve":"CVE-2026-91087","cvss":7.3,"epss":0.0064,"slug":"cve-2026-91087-gpac-use-after-free-in-media-object-compositor","title":"GPAC use-after-free in media object compositor","severity":"high","exploited":false,"published_at":"2026-09-15T07:16:34.237+00:00","url":"https://junglewise.ai/threats/cve-2026-91087-gpac-use-after-free-in-media-object-compositor"},{"cve":"CVE-2026-93331","cvss":7.3,"epss":0.0054,"slug":"cve-2026-93331-gpac-out-of-bounds-read-in-rtp-depacketizer","title":"GPAC out-of-bounds read in RTP depacketizer","severity":"high","exploited":false,"published_at":"2026-09-18T02:17:08.78+00:00","url":"https://junglewise.ai/threats/cve-2026-93331-gpac-out-of-bounds-read-in-rtp-depacketizer"},{"cve":"CVE-2026-79522","cvss":6.5,"epss":0.0054,"slug":"cve-2026-79522-gpac-out-of-bounds-read-in-downloader-http-client","title":"GPAC out-of-bounds read in downloader HTTP client","severity":"medium","exploited":false,"published_at":"2026-09-09T21:17:04.683+00:00","url":"https://junglewise.ai/threats/cve-2026-79522-gpac-out-of-bounds-read-in-downloader-http-client"},{"cve":"CVE-2026-79514","cvss":6.5,"epss":0.0054,"slug":"cve-2026-79514-gpac-out-of-bounds-read-in-downloader-via-chunked-http-response","title":"GPAC out-of-bounds read in downloader via chunked HTTP response","severity":"medium","exploited":false,"published_at":"2026-09-09T21:17:04.273+00:00","url":"https://junglewise.ai/threats/cve-2026-79514-gpac-out-of-bounds-read-in-downloader-via-chunked-http-response"},{"cve":"CVE-2026-79513","cvss":6.5,"epss":0.0037,"slug":"cve-2026-79513-gpac-divide-by-zero-in-dash-client-timeline-parsing","title":"GPAC divide-by-zero in dash_client timeline parsing","severity":"medium","exploited":false,"published_at":"2026-09-09T21:17:04.15+00:00","url":"https://junglewise.ai/threats/cve-2026-79513-gpac-divide-by-zero-in-dash-client-timeline-parsing"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}