CVE-2026-91088 | GPAC up to f1219cde URL utils/url.c gf_url_concatenate_ex heap-based overflow
A vulnerability, which was classified as problematic, has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-91088. An attack has to be approached locally. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More