{"id":"CVE-2026-91087","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-91087","summary":"A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a…","details":"A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is advised.","published":"2026-09-15T07:16:34.237","modified":"2026-09-15T07:16:34.237","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/gpac/gpac/commit/e34f4ba349d55cd1849f0bcf4cf46552732e2db7","label":"gpac/gpac@e34f4ba"},"references":[{"type":"WEB","url":"https://github.com/gpac/gpac/"},{"type":"WEB","url":"https://github.com/gpac/gpac/commit/e34f4ba349d55cd1849f0bcf4cf46552732e2db7"},{"type":"WEB","url":"https://github.com/gpac/gpac/issues/3807"},{"type":"WEB","url":"https://github.com/gpac/gpac/releases/tag/abi-16.24"},{"type":"WEB","url":"https://github.com/user-attachments/files/30399593/poc_12_info.zip"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-91087"},{"type":"WEB","url":"https://vuldb.com/submit/919756"},{"type":"WEB","url":"https://vuldb.com/vuln/403649"},{"type":"WEB","url":"https://vuldb.com/vuln/403649/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T07:16:34.237"}}