Gpac is a multimedia framework and toolkit with a surprisingly large vulnerability footprint concentrated in a narrowly scoped product portfolio, centered on the widely used MP4Box utility. The exposure recurs consistently through memory-safety weaknesses including NULL-pointer dereferences, out-of-bounds reads and writes, and integer-overflow conditions that cascade into buffer overflows, typical of C-based media parsing and encoding libraries that process untrusted input. These classes of flaw arise from the complexity of multimedia container formats and the low-level buffer manipulation required to parse and transcode media files, making them a durable structural signature of this vendor's codebase. Defenders should treat Gpac as a supply-chain component and monitor downstream products and workflows that integrate this toolkit or invoke MP4Box, since vulnerability patches may require coordinated updates across dependent applications. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gpac over time
Signals from CVEs in this vendor scope (406 CVEs).
406 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60467HIGH A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service | Jun 24, 2026 | 7.5 | 35 | NO | NO |
CVE-2025-60474HIGH A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin | Jun 24, 2026 | 7.5 | 35 | NO | NO |
CVE-2025-60464HIGH A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via | Jun 25, 2026 | 7.8 | 33 | NO | NO |
CVE-2018-13006CRITICAL An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. | Jun 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-13005CRITICAL An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. | Jun 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2025-52292HIGH A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-52293HIGH A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplyin | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-55657HIGH A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craft | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-33144HIGH GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in | Mar 20, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-70298HIGH GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. | Jan 15, 2026 | 8.2 | 30 | NO | NO |
Signals from CVEs in this vendor scope (406 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gpac.
Media articles that mention a CVE ID that affects a product developed by Gpac — matched by CVE ID, not by vendor name.