Vulnerability Description
A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/gpac/gpac/
- https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a
- https://github.com/gpac/gpac/issues/3809
- https://github.com/gpac/gpac/releases/tag/abi-16.23
- https://github.com/user-attachments/files/30399830/poc_16_bt.zip
- https://vuldb.com/cve/CVE-2026-91089
- https://vuldb.com/submit/919758
- https://vuldb.com/vuln/403651
- https://vuldb.com/vuln/403651/cti
FAQ
What is CVE-2026-91089?
CVE-2026-91089 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible ...
How severe is CVE-2026-91089?
CVE-2026-91089 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91089?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.