CVE-2026-TBD - Use-after-free write in GPAC HTTP input filter error path
Summary CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19) Component: in_http.c (HTTP input filter) Vulnerability Type: Use-after-free (write) Vendor: GPAC Product: GPAC (libgpac / MP4Box / gpac) Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV; only HEAD is supported per GPAC policy) Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3747 closed 2026-07-23 Severity: Critical (9.2): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N Credit: Salim Largo (2ourc3) Description A heap use-after-free write exists in GPAC’s HTTP input filter, in httpin_notify_error(). When the filter’s error-notification path runs during session setup, gf_filter_setup_failure() can tear down the filter (freeing its context), but the function continues to write to that freed context afterward. ...