CVE Tools

Gpac

467 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Gpac, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Gpac CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gpac CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-013
2025-021
2025-031
2025-046
2025-050
2025-060
2025-0722
2025-0821
2025-090
2025-105
2025-110
2025-121
2026-0114
2026-021
2026-032
2026-040
2026-053
2026-0634
2026-070
2026-080
2026-093

Severity

How the 467 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical174%
  • High15633%
  • Medium28461%
  • Low92%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gpac.

  1. CVE-2026-79514An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab2...6.5
  2. CVE-2026-79513A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD S...6.5
  3. CVE-2026-79522An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in...6.5
  4. CVE-2025-60465A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafte...6.1
  5. CVE-2025-60464A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a craf...7.8
  6. CVE-2025-60468GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter...5.5
  7. CVE-2025-60467A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supply...7.5
  8. CVE-2025-60471A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via sup...5.5
  9. CVE-2025-60474A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.7.5
  10. CVE-2025-60466A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a craft...5.0
  11. CVE-2025-60473A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supply...5.5
  12. CVE-2025-55639GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Ser...6.5
  13. CVE-2025-55648A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.5.5
  14. CVE-2025-55642GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).6.5
  15. CVE-2025-55645A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store