PT-2026-91878 · Gpac · Gpac

·

CVE-2026-91088

·

Published

2026-09-15

·

Updated

2026-09-15

CVSS v3.1

4.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GPAC versions prior to abi-16.23
Description A heap-based buffer overflow occurs in the URL Handler component within the gf url concatenate ex() function located in the utils/url.c file. This issue requires local access to be exploited.
Recommendations Upgrade to version abi-16.23.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91088

Affected Products

Gpac