A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90686.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "f1219cde"
},
{
"last_affected": "f1219cde"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90686.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"306022364242235629130328359297815212919",
"206088938342289334820491774055816408092",
"178486080340384204396849864934168378800",
"133615900130763105904069414514133576565",
"134932731613750766153635197407119193008",
"255544935993175506527159661719941949262",
"21687019081543999159153193868474962353",
"199421332530636493151174755363157407767",
"108190035962844935856727737896489909290",
"118019428630215521230541654980653110357",
"132909969811350343415240137029306872151",
"202777438071222357639231809665167935998"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-037d9b2e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scene_manager/loader_bt.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "40763145288472464194306659601921403951",
"length": 2542
},
"id": "CVE-2026-90686-19967496",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/laser/lsr_dec.c",
"function": "lsr_read_update_value_indexed"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "16105583149812151471999334210603192810",
"length": 1078
},
"id": "CVE-2026-90686-308f596f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scenegraph/base_scenegraph.c",
"function": "gf_node_new"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"281019298259458676463365424540012473020",
"275896235085808606878425725130772821805",
"130603590817192246693146680083882143047",
"321874392087727225803289766742909458025"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-38d5d051",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scene_manager/loader_xmt.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "14178323622761817715395350180465721831",
"length": 13737
},
"id": "CVE-2026-90686-4b21933f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/filters/reframe_mpgvid.c",
"function": "mpgviddmx_process"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "85547673649109928289138629523661336633",
"length": 415
},
"id": "CVE-2026-90686-75a47ff9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scenegraph/base_scenegraph.c",
"function": "gf_node_get_field_count"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"167141752749197753404488438083409457812",
"326092195129265630213745422993286893457",
"159869321366254571110184260387312874738",
"48204977388491737899421780970414153436",
"41675050562946050008316010776304950177",
"237151400206892422361853859182916539572",
"291505054378878619914578754738364174015"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-9351ab29",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scene_manager/scene_dump.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "184390907810877883962621940172930985008",
"length": 4624
},
"id": "CVE-2026-90686-936396c3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scene_manager/scene_dump.c",
"function": "gf_sm_dump_command_list"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"205737173651227882028426109058360870717",
"106342432199821688007212536081677464860",
"234332166957168503823740292947981518532",
"76710928464697411233778552392204065261"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-942fc8a4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/utils/url.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228527673140987252699050697781744235064",
"length": 6913
},
"id": "CVE-2026-90686-b1d8ba7e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/utils/url.c",
"function": "gf_url_concatenate_ex"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"333119192066413005289346787011123998649",
"222385520634484405173077007711214776032",
"217699001116520478487079544509988740915",
"227094250156502314341330756939196407394",
"114440243379116008816231589087322987902",
"155438520616384194338033712019519109330",
"206117794108324762209039093613804082282",
"1030962229606997561293553420312101004"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-b6b6e792",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scenegraph/base_scenegraph.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "22739030460114073125806386582437443612",
"length": 20971
},
"id": "CVE-2026-90686-cb84c663",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scene_manager/loader_bt.c",
"function": "gf_bt_parse_bifs_command"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "99217466696966097108982473180514699456",
"length": 14180
},
"id": "CVE-2026-90686-d19808ef",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/scene_manager/loader_xmt.c",
"function": "xmt_parse_element"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "24638615923267983171239763894418229581",
"length": 1003
},
"id": "CVE-2026-90686-d89f6ac2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/laser/lsr_dec.c",
"function": "lsr_exec_command_list"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"234062135461165672950595085036794303320",
"158332041347350122388901037142795803133",
"137512909836376107911456467394400178580",
"226920696903312963842287946921535187606",
"5162996421463581710368257839378940089",
"134145799933799258836665775110286847243"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-dcc8f3cd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/filters/reframe_mpgvid.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"30992887268071951573122690046123505869",
"166217695735206303677796966687687262392",
"161533222389349170933045638037504324978",
"169244502898661978606153915466337173736",
"200591764783860200120385660075583553687",
"106016964253074850954557248197406864429",
"100402202148086010268953713508378287710",
"105026866591025536698346391198876736914",
"241700686751825445141331565946956083295",
"252569693518944515775165229271676532689",
"337856452302349256826384986632351569256",
"320005655943153915070363962236840965561",
"62394375347671003074559590066730891108",
"131512168616103476372699999379381642449",
"277962910014678496926015137760890258314"
],
"threshold": 0.9
},
"id": "CVE-2026-90686-e5149b39",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
"target": {
"file": "src/laser/lsr_dec.c"
}
}
]
"2026-09-15T08:10:57Z"