Gpac
Vendor:
First CVE: Mar 6, 2018 · Active for 8 years
402
Total CVEs
More Total CVEs than 75% of tracked products
44.7
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gpac over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2018
8 years ago
Most Recent CVE
Jun 25, 2026
33 days ago
CVE Severity & Scoring
Gpac402 CVEs
59%
37%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local323 (80.3%)
Network79 (19.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low402 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None57 (14.2%)
Unknown0 (0.0%)
Required345 (85.8%)
Privileges Required
Low17 (4.2%)
High0 (0.0%)
None385 (95.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (402 CVEs).
402 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60467HIGH A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service | Jun 24, 2026 | 7.5 | 33 | NO | NO |
CVE-2025-60474HIGH A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin | Jun 24, 2026 | 7.5 | 33 | NO | NO |
CVE-2025-60464HIGH A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via | Jun 25, 2026 | 7.8 | 32 | NO | NO |
CVE-2018-13006CRITICAL An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. | Jun 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-13005CRITICAL An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. | Jun 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2025-52292HIGH A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-52293HIGH A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplyin | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-55657HIGH A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craft | Jun 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-33144HIGH GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in | Mar 20, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-70298HIGH GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. | Jan 15, 2026 | 8.2 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (402 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (402 CVEs).
Media Mentions
Signals from CVEs in this product scope (402 CVEs).
Top CNAs Publishing CVEs For Gpac
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5-dev-rev288-g11067ea92-master | 4 | 5.5 | 0.3% | 0 | 0 |
| 2.5 | 1 | 8.4 | 0.4% | 0 | 0 |
| 2.4.0 | 10 | 6.5 | 0.3% | 0 | 0 |
| 2.4 | 8 | 6.8 | 0.4% | 0 | 0 |
| 2.3-dev-rev921-g422b78ecf-master | 2 | 6.7 | 0.4% | 0 | 0 |
| 2.3-dev-rev617-g671976fcc-master | 5 | 6.7 | 0.5% | 0 | 0 |
| 2.3-dev-rev605-gfc9e29089-master | 5 | 5.9 | 0.3% | 0 | 0 |
| 2.3-dev-rev588-g7edc40fee-master | 2 | 9.3 | 1.0% | 0 | 0 |
| 2.3-dev-rev573-g201320819-master | 1 | 5.5 | 0.3% | 0 | 0 |
| 2.3-dev-rev566-g50c2ab06f-master | 3 | 7.8 | 0.4% | 0 | 0 |
| 2.3-dev-rev40-g3602a5ded | 1 | 8.8 | 1.1% | 0 | 0 |
| 2.3-dev-rev381-g817a848f6-master | 4 | 5.5 | 0.3% | 0 | 0 |
| 2.3-dev-rev1-g4669ba229-master | 1 | 7.8 | 0.4% | 0 | 0 |
| 2.3.0-dev | 1 | 5.5 | 0.3% | 0 | 0 |
| 2.3.0 | 1 | 9.1 | 0.9% | 0 | 0 |
| 2.3 | 6 | 7.0 | 0.4% | 0 | 0 |
| 2.2-rev0-gab012bbfb-master | 2 | 6.7 | 0.4% | 0 | 0 |
| 2.2.1 | 2 | 7.5 | 1.3% | 0 | 0 |
| 2.1-dev-rev490-g68064e101-master | 1 | 8.8 | 0.8% | 0 | 0 |
| 2.1 | 2 | 6.5 | 0.7% | 0 | 0 |