CVE-2026-91091 Details
Description
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
A memory corruption vulnerability has been identified in GPAC versions prior to commit f1219cde. The issue arises in the Node Insertion component, specifically within the function gf_node_list_insert_child, located in scenegraph/base_scenegraph.c. This vulnerability can be exploited remotely, leading to memory corruption.
Users are advised to upgrade to GPAC version abi-16.23, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gpac/gpac/ | [email protected] | Vendor |
| https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a | [email protected] | Source CodeVendor |
| https://github.com/gpac/gpac/issues/3811 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gpac/gpac/releases/tag/abi-16.23 | [email protected] | Release NotesVendor |
| https://github.com/user-attachments/files/30400179/poc_18_nstatx.zip | [email protected] | Broken LinkExploit |
| https://vuldb.com/cve/CVE-2026-91091 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/919761 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403653 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403653/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GPAC | <f1219cde |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion