Gpac MP4Box: 25 Vulnerabilities Disclosed, Many Remotely Exploitable
Key findings • 25 CVEs disclosed for Gpac and other software on September 13-14, 2026. • Gpac MP4Box component heavily impacted by memory corruption flaws. • Multiple vulnerabilities are …

Key findings
- 25 CVEs disclosed for Gpac and other software on September 13-14, 2026.
- Gpac MP4Box component heavily impacted by memory corruption flaws.
- Multiple vulnerabilities are remotely exploitable with public exploits available.
- Batch includes vulnerabilities from unrelated projects, requiring broad security attention.
- Users urged to update Gpac to patched versions promptly.
On September 13-14, 2026, a batch of 25 vulnerabilities was disclosed for the Gpac multimedia framework. The majority of these flaws, 22 in total, affect the MP4Box component, with many stemming from issues within the scenegraph module. These vulnerabilities range in severity from Low to Medium, with CVSS scores between 2.8 and 6.3. A significant number of these issues, including CVE-2026-90827, CVE-2026-90826, CVE-2026-90825, CVE-2026-90824, CVE-2026-90684, CVE-2026-90683, CVE-2026-90613, CVE-2026-90612, CVE-2026-90611, CVE-2026-90610, and CVE-2026-90609, were found to be related to memory corruption, such as use-after-free, out-of-bounds reads, null pointer dereferences, and buffer overflows. Several of these vulnerabilities, including CVE-2026-90794, CVE-2026-90793, CVE-2026-90792, CVE-2026-90791, CVE-2026-90687, CVE-2026-90686, CVE-2026-90578, and CVE-2026-90577, are noted as being remotely exploitable.
The disclosed vulnerabilities impact various functions within Gpac's scenegraph and related modules. For instance, CVE-2026-90827, CVE-2026-90825, and CVE-2026-90683 all relate to use-after-free vulnerabilities in the gf_node_deactivate_ex, gf_node_unregister, and gf_node_changed_internal functions respectively, all within the base_scenegraph.c file. Similarly, CVE-2026-90826 and CVE-2026-90684 involve out-of-bounds read and reachable assertion issues in gf_node_del and gf_node_get_field_count, also in base_scenegraph.c. CVE-2026-90794 and CVE-2026-90791 highlight use-after-free vulnerabilities in gf_sg_script_load and gf_node_unregister in vrml_tools.c and base_scenegraph.c, respectively.
Beyond the core Gpac MP4Box component, the batch also includes vulnerabilities in other areas. CVE-2026-90685, a reachable assertion, affects the lsr_exec_command_list function in laser/lsr_dec.c. CVE-2026-90686 points to a memory corruption vulnerability in gf_bt_report within scene_manager/loader_bt.c. Additionally, CVE-2026-90682 and CVE-2026-90681, while listed in the batch, appear to affect different projects: Matthias-Wandel jhead and GNU libredwg respectively, indicating a broader disclosure event that may have bundled unrelated findings.
The descriptions consistently mention that exploits for many of these vulnerabilities are publicly available and may be utilized, underscoring the urgency for users to update their Gpac installations. The affected versions are generally noted as being prior to specific commit hashes or release versions, with patches available in later releases. For example, several medium-severity vulnerabilities are linked to versions up to f1219cde or abi-16, with fixes expected in subsequent updates.
The disclosure of this batch of vulnerabilities, particularly those affecting the MP4Box component and featuring remote exploitability, presents a significant risk to users of Gpac. The prevalence of memory corruption flaws suggests a need for thorough code auditing and robust security practices within the project. Users are strongly advised to consult the official Gpac advisories and apply updates as soon as possible to mitigate the risks associated with these publicly known exploits. The inclusion of vulnerabilities from unrelated projects within this batch also warrants careful attention from security teams to ensure all affected software is identified and patched.
Three additional CVEs, CVE-2026-90599, CVE-2026-90598, and CVE-2026-90578, were also disclosed on September 13th, 2026. CVE-2026-90599 is a cross-site request forgery vulnerability in Rizwan17 inventory-management-system. CVE-2026-90598 is an authorization bypass in jaygajera17 E-commerce-project-springBoot. CVE-2026-90578 is a use-after-free vulnerability in Gpac's MP4Box component, specifically in the gf_list_count function within utils/list.c. These vulnerabilities, while part of the same disclosure window, affect different projects and components, highlighting a diverse set of security issues revealed in this period. CVE-2026-90577, another Gpac MP4Box vulnerability, involves heap-based buffer overflow in gf_node_get_field.
The batch also includes CVE-2026-90622, a null pointer dereference in GNU libredwg 0.13.4, affecting the DWG_TABLE function in src/dwg.spec. This further emphasizes the varied nature of the disclosed vulnerabilities, spanning multiple software projects and types of security flaws. The common thread across many of these issues is the availability of public exploits, increasing the immediate threat landscape for users.
The Gpac project, in particular, faces a significant number of vulnerabilities, with many related to memory safety within its MP4Box component. The functions gf_node_deactivate_ex, gf_node_del, gf_node_unregister, gf_sg_dom_event_bubble, gf_sg_script_load, gf_node_get_name, gf_node_list_get_child, gf_node_changed_internal, gf_bt_report, lsr_exec_command_list, gf_node_get_field_count, gf_sm_dump_command_list, xmt_parse_element, gf_svg_attributes_copy, gf_list_count, and gf_node_get_field are all implicated in various memory-related vulnerabilities. The remote exploitability of several of these issues, such as CVE-2026-90794, CVE-2026-90793, CVE-2026-90792, CVE-2026-90791, CVE-2026-90687, CVE-2026-90686, CVE-2026-90577, and CVE-2026-90578, necessitates prompt patching.
The disclosure on September 13-14, 2026, encompasses 25 CVEs affecting Gpac and other software. The Gpac MP4Box component is heavily impacted, with numerous memory corruption vulnerabilities including use-after-free, buffer overflows, and null pointer dereferences. Several of these flaws are remotely exploitable, and public exploits are available, increasing the risk to users. Updates are available for affected versions, and users are urged to apply them promptly. The batch also includes vulnerabilities in unrelated projects like Matthias-Wandel jhead, GNU libredwg, Rizwan17 inventory-management-system, and jaygajera17 E-commerce-project-springBoot, indicating a broad disclosure event. The presence of multiple memory safety issues in Gpac's scenegraph and related files underscores the need for diligent security practices and regular updates. Patches for Gpac are available in newer versions, and users should prioritize upgrading to mitigate the risks associated with these publicly disclosed and exploitable vulnerabilities.