CVE-2026-91090Low· 3.9▾ SunlitA vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 21.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90824Low· 3.3A vulnerability has been found in GPAC 26.07.0
CVE-2026-90825Low· 3.3A vulnerability was found in GPAC 26.07.0
CVE-2026-90793Medium· 5.4A vulnerability has been found in GPAC up to f1219cde
CVE-2026-90794Medium· 6.3A vulnerability was found in GPAC up to f1219cde
CVE-2026-90687Medium· 6.3A vulnerability was determined in GPAC up to f1219cde
CVE-2026-90791Medium· 6.3A vulnerability was detected in GPAC up to f1219cde