---
id: CVE-2026-108539
title: A vulnerability was detected in GPAC up to 26.07.0
summary: >-
  A vulnerability was detected in GPAC up to 26.07.0. This affects the function
  gf_fq_pop of the file filter_core/filter_queue.c of the component MP4Box.
  Performing a manipulation results in use after free. The attack may be
  initiated remo…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-416
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T05:16:53.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108539'
references:
  - url: 'https://github.com/user-attachments/files/31288202/PoC.zip'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-108539'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/941995'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/416194'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/416194/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-10-11T05:42:11.233Z'
---

## Overview

A vulnerability was detected in GPAC up to 26.07.0. This affects the function gf_fq_pop of the file filter_core/filter_queue.c of the component MP4Box. Performing a manipulation results in use after free. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
