---
id: CVE-2026-90792
title: A flaw has been found in GPAC up to f1219cde
summary: >-
  A flaw has been found in GPAC up to f1219cde. This issue affects the function
  gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the
  component MP4Box. This manipulation of the argument Target causes null pointer
  dereferen…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
  - CWE-476
product: GPAC
affected:
  - GPAC f1219cde
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90792'
references:
  - url: 'https://github.com/Ech06/CVE_submit/blob/main/gpac_3802.md'
    label: cna@vuldb.com
  - url: 'https://github.com/gpac/gpac/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975
    label: cna@vuldb.com
  - url: 'https://github.com/gpac/gpac/issues/3802'
    label: cna@vuldb.com
  - url: 'https://github.com/gpac/gpac/releases/tag/abi-16.23'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90792'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/914123'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403298'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403298/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T16:48:14.759870Z'
ingestedAt: '2026-09-14T15:23:07.426Z'
epss: 0.00391
epssPercentile: 0.33009
---

## Overview

A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version abi-16.23 is capable of addressing this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
