GPAC vulnerabilities
CVEs whose affected-version data names the GPAC package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
37 CVEsRSS
CVE-2026-93331High· 7.3A vulnerability was identified in GPAC 26.08-DEV
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of…
CVE-2026-92474Low· 3.3PoCA security flaw has been discovered in GPAC 26.08-DEV
A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attac…
CVE-2026-92475Medium· 5.3A weakness has been identified in GPAC 26.08-DEV
A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires loca…
CVE-2026-92473Low· 3.3PoCA vulnerability was identified in GPAC 26.08-DEV
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to b…
CVE-2026-92472Low· 3.3PoCA vulnerability was determined in GPAC 26.08-DEV
A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The a…
CVE-2026-92399High· 7.3PoCA vulnerability was determined in GPAC 26.07.0
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to hea…
CVE-2026-91091Medium· 4.3PoCA vulnerability was identified in GPAC up to f1219cde
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption.…
CVE-2026-91090Low· 3.9A vulnerability was determined in GPAC up to f1219cde
A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the …
CVE-2026-91089Medium· 6.3A vulnerability was found in GPAC up to f1219cde
A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The ex…
CVE-2026-91088Medium· 4.8PoCA vulnerability has been found in GPAC up to f1219cde
A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be …
CVE-2026-91087High· 7.3PoCA flaw has been found in GPAC up to f1219cde
A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may …
CVE-2026-91086Medium· 6.3PoCA security vulnerability has been detected in GPAC up to f1219cde
A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based …
CVE-2026-90825Low· 3.3PoCA vulnerability was found in GPAC 26.07.0
A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only…
CVE-2026-90826Low· 2.8PoCA vulnerability was determined in GPAC 26.07.0
A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to…
CVE-2026-90827Low· 3.3PoCA vulnerability was identified in GPAC 26.07.0
A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out l…
CVE-2026-90824Low· 3.3PoCA vulnerability has been found in GPAC 26.07.0
A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow. The attack can only b…
CVE-2026-90794Medium· 6.3PoCA vulnerability was found in GPAC up to f1219cde
A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a manipulation results in use after free. It is possible to …
CVE-2026-90793Medium· 5.4PoCA vulnerability has been found in GPAC up to f1219cde
A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed fro…
CVE-2026-90613Low· 3.3PoCA security flaw has been discovered in GPAC up to f1219cde
A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The…
CVE-2026-90612Low· 3.3PoCA vulnerability was identified in GPAC up to f1219cde
A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be car…
CVE-2026-90611Low· 3.3PoCA vulnerability was determined in GPAC up to f1219cde
A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is re…
CVE-2026-90610Low· 3.3PoCA vulnerability was found in GPAC up to f1219cde
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only…
CVE-2026-90685Low· 2.8PoCA vulnerability has been found in GPAC up to f1219cde
A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is requi…
CVE-2026-90684Low· 2.8PoCA flaw has been found in GPAC up to f1219cde
A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable asserti…
CVE-2026-90683Low· 3.3PoCA vulnerability was detected in GPAC up to f1219cde
A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locall…
CVE-2026-90687Medium· 6.3PoCA vulnerability was determined in GPAC up to f1219cde
A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is poss…
CVE-2026-90792Medium· 4.3PoCA flaw has been found in GPAC up to f1219cde
A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereferen…
CVE-2026-90609Low· 3.3PoCA vulnerability has been found in GPAC up to f1219cde
A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be p…
CVE-2026-90791Medium· 6.3PoCA vulnerability was detected in GPAC up to f1219cde
A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can …
CVE-2026-90686Medium· 5.3PoCA vulnerability was found in GPAC up to f1219cde
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remot…