CVE-2026-108538 | GPAC up to 26.07.0 MP4Box utils/os_thread.c gf_mx_v use after free
A vulnerability classified as critical was found in GPAC up to 26.07.0. The impacted element is the function gf_mx_v of the file utils/os_thread.c of the component MP4Box. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-108538. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More