{"id":"CVE-2026-90610","title":"A vulnerability was found in GPAC up to f1219cde","summary":"A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-119","CWE-126"],"product":"GPAC","affected":["GPAC f1219cde"],"published":"2026-09-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T14:17:23.973","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90610","references":[{"url":"https://github.com/gpac/gpac/","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/issues/3819","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/releases/tag/abi-16.23","label":"cna@vuldb.com"},{"url":"https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln%20GPAC%20MP4Box%20Heap-Buffer-Overflow%20READ%20size%2020%20in%20gf_svg_attributes_copy.md","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90610","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/913516","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403192","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403192/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T13:42:19.263303Z"},"epss":0.00118,"epssPercentile":0.01937,"ingestedAt":"2026-09-14T15:23:07.467Z","slug":"CVE-2026-90610","body":"## Overview\n\nA vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":30,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":203627,"id":"CVE-2026-90610","ts":1789483131791,"field":"exploit_available","old":"false","new":"true"}]}