Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234. | |
| Title | GPAC MP4Box base_scenegraph.c gf_node_unregister assertion | |
| First Time appeared |
Gpac
Gpac gpac |
|
| Weaknesses | CWE-617 | |
| CPEs | cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gpac
Gpac gpac |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T04:45:12.988Z
Reserved: 2026-09-13T04:55:25.133Z
Link: CVE-2026-90683
No data.
Status : Received
Published: 2026-09-14T05:16:58.900
Modified: 2026-09-14T05:16:58.900
Link: CVE-2026-90683
No data.
OpenCVE Enrichment
No data.