CVE-2026-90573 Details
Description
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.
A null pointer dereference vulnerability has been identified in GPAC versions prior to the commit f1219cde. The issue arises in the MP4Box component, specifically within the function gf_sg_mfurl_del, located in scenegraph/vrml_tools.c. This vulnerability requires local access to exploit and leads to a segmentation fault, causing a denial-of-service condition. The issue can be triggered when MP4Box processes a crafted MP4 file with the '-nstatx' option, which causes the application to traverse an untrusted embedded scene graph containing a malformed node. This node's URL field is improperly initialized, resulting in the null pointer dereference during the scene graph teardown process.
Users are advised to upgrade to GPAC version abi-16.23 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gpac/gpac/issues/3814 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gpac/gpac/ | [email protected] | ProductVendor |
| https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a | [email protected] | Source CodeVendor |
| https://github.com/gpac/gpac/issues/3814 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gpac/gpac/releases/tag/abi-16.23 | [email protected] | Release NotesVendor |
| https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-gf_sg_mfurl_del-NULL-Pointer-Dereference.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-90573 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/912814 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403158 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/403158/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GPAC | f1219cde |
CPE
Remediation
| |
| GPAC MP4Box | f1219cde |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion