{"id":"CVE-2026-90683","title":"A vulnerability was detected in GPAC up to f1219cde","summary":"A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locall…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-617"],"product":"GPAC","affected":["GPAC f1219cde"],"published":"2026-09-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:19:37.977","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90683","references":[{"url":"https://github.com/gpac/gpac/","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/issues/3823","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/releases/tag/abi-16.23","label":"cna@vuldb.com"},{"url":"https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln%20GPAC%20MP4Box%20Assertion%20Failure%20assert(num_instances).md","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90683","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/913780","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403216","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403216/cti","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/issues/3823","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T17:22:17.243434Z"},"epss":0.00118,"epssPercentile":0.01937,"ingestedAt":"2026-09-14T15:23:07.466Z","slug":"CVE-2026-90683","body":"## Overview\n\nA vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":30,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":204346,"id":"CVE-2026-90683","ts":1789494100155,"field":"exploit_available","old":"false","new":"true"}]}