{"id":"CVE-2026-91090","title":"A vulnerability was determined in GPAC up to f1219cde","summary":"A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the …","severity":"low","cvss":3.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-119","CWE-121"],"product":"GPAC","affected":["GPAC f1219cde"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:17:53.157","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91090","references":[{"url":"https://github.com/gpac/gpac/","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/commit/9eb40df4448b88d6a6ce3454657c06f47eff0b24","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/issues/3810","label":"cna@vuldb.com"},{"url":"https://github.com/gpac/gpac/releases/tag/abi-16.23","label":"cna@vuldb.com"},{"url":"https://github.com/user-attachments/files/30399928/poc_17_nstatx.zip","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-91090","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/919759","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403652","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403652/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"epss":0.00123,"epssPercentile":0.02374,"ingestedAt":"2026-09-15T08:34:10.542Z","slug":"CVE-2026-91090","body":"## Overview\n\nA vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":21,"depthScoreParts":{"impact":21.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}