Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90577— GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow

Quick assessment

Affected
n/a GPAC
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GPAC(版本号 f1219cde 及之前)中检测到一个漏洞。 受影响组件:MP4Box 组件中 文件里的 函数。 漏洞类型:堆缓冲区溢出(heap-based buffer overflow)。当对节点字段执行某些操作时可能触发该溢出。 攻击方式:仅可通过本地访问进行利用。 公开状态:该漏洞的利用方法(Exploit)已经公开,可能被攻击者使用。 修复方案:升级至 abi-16.23 版本即可解决此问题。 补丁标识:对应的修复补丁提交哈希值为 。 建议措施**:应将受影响的组件升级至修复版本,以消除风险。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90577

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- GPAC f1219cde cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-90577

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90577

登录查看更多情报信息。

Patches & Fixes for CVE-2026-90577 (1)

Vendor Pages for CVE-2026-90577 (1)

Other References for CVE-2026-90577 (5)

Same Patch Batch · n/a · 2026-09-13 · 6 CVEs total

CVE-2026-90578 5.3 MEDIUM GPAC MP4Box list.c gf_list_count use after free
CVE-2026-90529 3.5 LOW DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting
CVE-2026-90576 3.3 LOW GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference
CVE-2026-90573 3.3 LOW GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference
CVE-2025-70819 Zettlab D6 Ultra 1.7.0以下路径穿越挂载漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-90577

No comments yet


Leave a comment