CVE-2026-108539 | GPAC up to 26.07.0 MP4Box filter_queue.c gf_fq_pop use after free
A vulnerability, which was classified as critical, has been found in GPAC up to 26.07.0. This affects the function gf_fq_pop of the file filter_core/filter_queue.c of the component MP4Box. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-108539. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More