Gpac
467 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Gpac, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Gpac CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 3 |
| 2025-02 | 1 |
| 2025-03 | 1 |
| 2025-04 | 6 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 22 |
| 2025-08 | 21 |
| 2025-09 | 0 |
| 2025-10 | 5 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 14 |
| 2026-02 | 1 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 3 |
| 2026-06 | 34 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 3 |
Severity
How the 467 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical17
- High156
- Medium284
- Low9
Latest CVEs
The 15 most recently published vulnerabilities affecting Gpac.
- CVE-2026-79514An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab2...6.5
- CVE-2026-79513A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD S...6.5
- CVE-2026-79522An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in...6.5
- CVE-2025-60465A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafte...6.1
- CVE-2025-60464A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a craf...7.8
- CVE-2025-60468GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter...5.5
- CVE-2025-60467A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supply...7.5
- CVE-2025-60471A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via sup...5.5
- CVE-2025-60474A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.7.5
- CVE-2025-60466A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a craft...5.0
- CVE-2025-60473A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supply...5.5
- CVE-2025-55639GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Ser...6.5
- CVE-2025-55648A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.5.5
- CVE-2025-55642GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).6.5
- CVE-2025-55645A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.5.5
Product grouping is registry-driven, with AI assist and human review. How it works