GPAC Project develops a multimedia framework and toolset for MPEG standards authoring and playback, components that, despite narrow product scope, often operate on untrusted media inputs. Its vulnerability profile centers on memory-safety issues, particularly improper bounds restriction and out-of-bounds writes that arise from parser complexity when handling crafted audio and video streams. Severity, exploitation, and exposure figures are shown in the live-stats panel alongside this summary.
The number and severity of CVEs published that impact products developed by Gpac Project over time
Signals from CVEs in this vendor scope (406 CVEs).
406 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60467HIGH A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service | Jun 24, 2026 | 7.5 | 35 | NO | NO |
CVE-2025-60474HIGH A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin | Jun 24, 2026 | 7.5 | 35 | NO | NO |
CVE-2025-60464HIGH A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via | Jun 25, 2026 | 7.8 | 33 | NO | NO |
CVE-2018-13006CRITICAL An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. | Jun 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-13005CRITICAL An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. | Jun 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2025-52292HIGH A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-52293HIGH A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplyin | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-55657HIGH A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craft | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-33144HIGH GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in | Mar 20, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-70298HIGH GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. | Jan 15, 2026 | 8.2 | 30 | NO | NO |
Signals from CVEs in this vendor scope (406 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gpac Project.
Media articles that mention a CVE ID that affects a product developed by Gpac Project — matched by CVE ID, not by vendor name.