Post

CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability

CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability

CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability

The CVE-2026-90824 vulnerability, concerning a stack-based buffer overflow in GPAC MP4Box, was officially reported on September 14, 2026. Affected is the function gf_sg_dom_event_bubble located in the file src/scenegraph/dom_events.c of the MP4Box component. This vulnerability allows for a stack-based buffer overflow, which can only be exploited from a local environment.

Key Details:

  • Affected Version: GPAC 26.07.0
  • Recommended Action: Upgrade to version abi-16.23 to mitigate this issue.
  • Patch Identifier: 9eb40df4448b88d6a6ce3454657c06f47eff0b24

The exploit has been publicly disclosed and is currently under active monitoring. We are scanning GitHub repositories to detect new proof-of-concept exploits related to this vulnerability. A collection of public exploits and proof-of-concepts has already been identified.

Understanding the history of this vulnerability is crucial for assessing its severity and exploitability. The vulnerability has been assigned a CVSS V4.0 score of:

  • AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Additionally, the CVSS V3.1 score is:

  • AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.

The CVSS V2 score is:

  • AV:L/AC:L/Au:S/C:N/I:N/A:P.

The associated Common Weakness Enumerations (CWEs) are CWE-119 and CWE-121.

For further details, you can read the complete article here: Read full article

🚀 Stay informed and secure!

This post is licensed under CC BY 4.0 by the author.