Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component. | |
| Title | GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruption | |
| First Time appeared |
Gpac
Gpac gpac |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gpac
Gpac gpac |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-15T07:45:10.116Z
Reserved: 2026-09-14T18:00:05.879Z
Link: CVE-2026-91091
No data.
Status : Received
Published: 2026-09-15T08:17:07.000
Modified: 2026-09-15T08:17:07.000
Link: CVE-2026-91091
No data.
OpenCVE Enrichment
Updated: 2026-09-15T10:30:12Z
-
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer