Gpac
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Gpac product.
RSS Feeds for Gpac security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Gpac products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Gpac Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 103 vulnerabilities in Gpac with an average score of 5.3 out of ten. Last year, in 2025 Gpac had 6 security vulnerabilities published. That is, 97 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.88
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 103 | 5.32 |
| 2025 | 6 | 6.20 |
| 2024 | 17 | 6.90 |
| 2023 | 84 | 6.76 |
| 2022 | 98 | 6.20 |
| 2021 | 116 | 6.75 |
| 2020 | 9 | 5.50 |
| 2019 | 23 | 7.03 |
| 2018 | 3 | 9.80 |
It may take a day or so for new Gpac vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Gpac Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-93331 | Sep 18, 2026 |
GPAC 26.08-DEV RTP Depacketizer OOB Read via gf_rtp_parse_ttxtA vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded. |
|
| CVE-2026-92475 | Sep 16, 2026 |
A weakness has been identified in GPAC 26.08-DEVA weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. Upgrading to version abi-16.26 will fix this issue. Patch name: c74a3065038ede35c1c7b75fa493a69ef6bcdb84. It is recommended to upgrade the affected component. |
|
| CVE-2026-92474 | Sep 16, 2026 |
A security flaw has been discovered in GPAC 26.08-DEVA security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.24 mitigates this issue. The patch is identified as e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is recommended. |
|
| CVE-2026-92473 | Sep 16, 2026 |
A vulnerability was identified in GPAC 26.08-DEVA vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component. |
|
| CVE-2026-92472 | Sep 16, 2026 |
A vulnerability was determined in GPAC 26.08-DEVA vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.24 is sufficient to fix this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. The affected component should be upgraded. This issue is distinct from CVE-2026-90827. |
|
| CVE-2026-92399 | Sep 16, 2026 |
A vulnerability was determined in GPAC 26.07.0A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 is able to mitigate this issue. This patch is called 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12. Upgrading the affected component is recommended. |
|
| CVE-2026-91091 | Sep 15, 2026 |
GPAC Node Insertion Memory Corruption (gf_node_list_insert_child)A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component. |
|
| CVE-2026-91090 | Sep 15, 2026 |
GPAC stack-based buffer overflow in gf_node_activate_ex before 16.23A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded. |
|
| CVE-2026-91089 | Sep 15, 2026 |
GPAC Use-After-Free in gf_node_get_name_and_id before abi-16.23A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is recommended to address this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component. |
|
| CVE-2026-91088 | Sep 15, 2026 |
GPAC URLH Heap Overflow via gf_url_concatenate_ex < f1219cde, fixed in abi-16.23A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component. |
|