{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/gpac/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-91087"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GPAC (\u003c abi-16.24)","GPAC (26.07.0)","GPAC (26.08-DEV)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-corruption","remote-code-execution","cve"],"_cs_type":"advisory","_cs_vendors":["GPAC"],"content_html":"\u003cp\u003eA use-after-free vulnerability has been identified in the GPAC multimedia framework, specifically affecting the 'gf_mo_get_od_id' function within 'compositor/media_object.c'. The flaw exists in all versions up to f1219cde. This vulnerability allows for remote exploitation when a user processes a specifically crafted malicious media file. Successful exploitation leads to memory corruption, which may result in application crashes or the potential for arbitrary code execution. As public exploit code for this vulnerability is currently available, it poses a significant risk to systems processing untrusted media content. The issue is addressed in the GPAC project by upgrading to version 'abi-16.24' or applying the patch identified by commit 'e34f4ba349d55cd1849f0bcf4cf46552732e2db7'. Organizations using GPAC as a library or standalone tool should prioritize patching.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability is rated with a CVSS v3.1 base score of 7.3, reflecting its high impact and remote exploitability. Successful exploitation allows for unauthorized memory access, potentially leading to service disruption through crashes or exploitation as an entry point for remote code execution. This impacts any environment utilizing GPAC to parse or render multimedia content, such as media players, streaming servers, or content transcoding pipelines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of GPAC to version 'abi-16.24' or later.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, apply patch 'e34f4ba349d55cd1849f0bcf4cf46552732e2db7' to the 'compositor/media_object.c' source file.\u003c/li\u003e\n\u003cli\u003eMonitor file processing services that ingest external media for unexpected process crashes or anomalous memory usage.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T04:02:44Z","date_published":"2026-09-15T07:39:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gpac-uaf/","summary":"A use-after-free vulnerability in the GPAC compositor component (CVE-2026-91087) allows remote attackers to trigger memory corruption via malicious media files.","title":"Use-After-Free Vulnerability in GPAC Compositor","url":"https://feed.craftedsignal.io/briefs/2026-09-gpac-uaf/"}],"language":"en","title":"CraftedSignal Threat Feed - GPAC","version":"https://jsonfeed.org/version/1.1"}