CVE-2026-90824 | GPAC 26.07.0 MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflow (Issue 3804)

SecurityVulns

A vulnerability classified as problematic has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow.

This vulnerability is referenced as CVE-2026-90824. The attack can only be performed from a local environment. Furthermore, an exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More