CVE-2026-91087
A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c
CVSS
7.3
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 15 sept 2026 · Última mod.: 15 sept 2026 · CWE-119 · CWE-416
Sin historial EPSS suficiente todavía.
A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.
- github.comhttps://github.com/gpac/gpac/
- github.comhttps://github.com/gpac/gpac/commit/e34f4ba349d55cd1849f0bcf4cf46552732e2db7
- github.comhttps://github.com/gpac/gpac/issues/3807
- github.comhttps://github.com/gpac/gpac/releases/tag/abi-16.24
- github.comhttps://github.com/user-attachments/files/30399593/poc_12_info.zip
- vuldb.comhttps://vuldb.com/cve/CVE-2026-91087
- vuldb.comhttps://vuldb.com/submit/919756
- vuldb.comhttps://vuldb.com/vuln/403649
- vuldb.comhttps://vuldb.com/vuln/403649/cti