CVE-2026-90792
GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version abi-16.23 is capable of addressing this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.
| CWE | CWE-476 CWE-404 |
| Vendor | n/a |
| Product | gpac |
| Published | Sep 14, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a gpac
Be the first to know when new medium vulnerabilities affecting n/a gpac are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / GPAC
f1219cde
References
vuldb.com: https://vuldb.com/vuln/403298 vuldb.com: https://vuldb.com/vuln/403298/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90792 vuldb.com: https://vuldb.com/submit/914123 github.com: https://github.com/gpac/gpac/issues/3802 github.com: https://github.com/Ech06/CVE_submit/blob/main/gpac_3802.md github.com: https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975 github.com: https://github.com/gpac/gpac/releases/tag/abi-16.23 github.com: https://github.com/gpac/gpac/
Credits
๐ Ech06 (VulDB User)