Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/gpac/gpac

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-91091 is a medium severity memory corruption vulnerability in the GPAC software, specifically in the function gf_node_list_insert_child within the Node Insertion component. This vulnerability affects GPAC versions up to commit f1219cde. The flaw allows remote attackers to cause memory corruption, and public exploit code is available. The issue is resolved by upgrading to GPAC version abi-16.23.

Join the discussion
0

CVE-2026-91090 is a stack-based buffer overflow vulnerability in the GPAC multimedia framework affecting the function gf_node_activate_ex in scenegraph/base_scenegraph.c. The issue affects GPAC versions up to commit f1219cde. Exploitation requires local access and involves low complexity with limited privileges. The vulnerability has a low CVSS score of 2.4. Upgrading to version abi-16.23 resolves the issue.

Join the discussion
0

CVE-2026-91089 is a use-after-free vulnerability in the GPAC multimedia framework affecting the function gf_node_get_name_and_id in scenegraph/base_scenegraph.c. This vulnerability allows remote attackers to exploit the flaw, potentially leading to memory corruption. An exploit has been publicly disclosed. The issue is addressed by upgrading to GPAC version abi-16.23, which contains the patch identified by commit 49dee5cad329cfed310c1682703df7daa47df31a.

Join the discussion
0

CVE-2026-91088 is a heap-based buffer overflow vulnerability in the GPAC project's URL Handler component, specifically in the gf_url_concatenate_ex function of utils/url.c. This vulnerability affects GPAC versions up to commit f1219cde. Exploitation requires local access with low privileges and user interaction. The issue is addressed by upgrading to GPAC version abi-16.23.

Join the discussion
0

CVE-2026-91087 is a use-after-free vulnerability in the GPAC multimedia framework affecting the gf_mo_get_od_id function in compositor/media_object.c. This flaw can be triggered remotely and may lead to memory corruption. An exploit is publicly available. The issue is resolved by upgrading to GPAC version abi-16.24.

Join the discussion
0

CVE-2026-91086 is a heap-based buffer overflow vulnerability in the GPAC MPEG Video Reframer component, specifically in the mpgviddmx_process function. This vulnerability affects GPAC versions up to commit f1219cde. The flaw can be exploited remotely and has been publicly disclosed. A patch is available in version abi-16.23, which addresses this issue. Users are advised to upgrade to this version to mitigate the risk.

Join the discussion

A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to mitigate this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.

Join the discussion

A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 can resolve this issue. Patch name: afca1f1181668d85941d51ed1adf647807d5d975. It is advisable to upgrade the affected component.

Join the discussion

A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.

Join the discussion
0

CVE-2026-90827 is a use-after-free vulnerability in GPAC version 26.07.0 affecting the function gf_node_deactivate_ex in the MP4Box component. The vulnerability requires local access to exploit and can lead to memory corruption. A patch is available in version abi-16.23 that mitigates this issue.

Join the discussion

Showing 1 to 10 of 79 results

Filters:Package: pkg:github/gpac/gpac
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses