Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

gpac — Vulnerabilities & Security Advisories 46

All 46 CVE vulnerabilities found in gpac, with AI-generated Chinese analysis, references, and POCs.

This page serves as a vulnerability aggregation resource for GPAC, focusing on Common Weakness Enumeration (CWE) types associated with this open-source multimedia framework. It compiles a comprehensive collection of security flaws, including buffer overflows, injection attacks, and memory corruption issues, covering advisory reports from the early 2010s through to the most recent patches released in the current year. Users can utilize this hub to track vendor-specific advisories and understand the evolution of specific weakness classes within the GPAC codebase. Additionally, the page allows for the lookup of a product’s vulnerability history, providing a chronological view of security incidents and their remediation status. By centralizing these data points, the resource aims to assist developers, security researchers, and system administrators in assessing risk profiles and prioritizing patch management efforts. The content is organized to facilitate deep analysis of recurring security patterns, enabling stakeholders to identify systemic weaknesses rather than isolated incidents. This approach supports a more proactive stance toward software maintenance and compliance. Readers are encouraged to explore the detailed entries to gain insights into how specific vulnerabilities were exploited and mitigated over time. The aggregated information reflects a continuous effort to maintain transparency regarding the security posture of GPAC, ensuring that all relevant data is accessible for informed decision-making and continuous improvement of the software’s resilience against potential threats.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-15185 GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds CWE-125 3.3 Low2026-07-09
CVE-2025-15668 GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow CWE-122 3.3 Low2026-07-06
CVE-2025-15667 GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free CWE-415 3.3 Low2026-07-06
CVE-2026-14801 GPAC TeXML File load_text.c txtin_probe_duration divide by zero CWE-369 3.3 Low2026-07-06
CVE-2026-14790 GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference CWE-476 3.3 Low2026-07-06
CVE-2026-13523 GPAC ISOBMFF base_encoding.c data amplification CWE-409 3.3 Low2026-06-29
CVE-2026-9572 GPAC MP4Box media.c Media_GetSample memory leak CWE-401 3.3 Low2026-05-26
CVE-2026-9567 GPAC MP4Box isom_intern.c MergeFragment null pointer dereference CWE-476 3.3 Low2026-05-26
CVE-2026-8124 GPAC box_code_base.c sidx_box_read allocation of resources CWE-770 3.3 Low2026-05-08
CVE-2026-7135 GPAC MP4Box box_code_base.c elng_box_read out-of-bounds CWE-125 5.3 Medium2026-04-27
CVE-2026-33144 GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing) CWE-787 5.8 Medium2026-03-20
CVE-2026-4185 GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow CWE-121 6.3 Medium2026-03-15
CVE-2026-4016 GPAC SVG Parser load_svg.c svgin_process out-of-bounds write CWE-787 5.3 Medium2026-03-12
CVE-2026-4015 GPAC TeXML File load_text.c txtin_process_texml stack-based overflow CWE-121 5.3 Medium2026-03-12
CVE-2026-27821 GPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer Overflow CWE-121 8.1AIHighAI2026-02-26
CVE-2026-1418 GPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds write CWE-787 5.3 Medium2026-01-26
CVE-2026-1417 GPAC filedump.c dump_isom_rtp null pointer dereference CWE-476 3.3 Low2026-01-26
CVE-2026-1416 GPAC filedump.c DumpMovieInfo null pointer dereference CWE-476 3.3 Low2026-01-26
CVE-2026-1415 GPAC media_export.c gf_media_export_webvtt_metadata null pointer dereference CWE-476 3.3 Low2026-01-26
CVE-2025-7797 GPAC dash_client.c gf_dash_download_init_segment null pointer dereference CWE-476 5.3 Medium2025-07-18
CVE-2024-6064 GPAC MP4Box loader_xmt.c xmt_node_end use after free CWE-416 5.3 Medium2024-06-17
CVE-2024-6063 GPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereference CWE-476 3.3 Low2024-06-17
CVE-2024-6062 GPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereference CWE-476 3.3 Low2024-06-17
CVE-2024-6061 GPAC MP4Box isoffin_read.c isoffin_process infinite loop CWE-835 3.3 Low2024-06-17
CVE-2023-1452 GPAC load_text.c buffer overflow CWE-120 5.3 Medium2023-03-17
CVE-2023-1449 GPAC av_parsers.c gf_av1_reset_state double free CWE-415 5.3 Medium2023-03-17
CVE-2023-1448 GPAC mpegts.c gf_m2ts_process_sdt heap-based overflow CWE-122 5.3 Medium2023-03-17
CVE-2023-0841 GPAC reframe_mp3.c mp3_dmx_process heap-based overflow CWE-122 6.3 Medium2023-02-15
CVE-2022-4202 GPAC lsr_dec.c lsr_translate_coords integer overflow CWE-189 6.3 Medium2022-11-29
CVE-2022-3957 GPAC SVG Parser svg_attributes.c svg_parse_preserveaspectratio memory leak CWE-404 4.3 Medium2022-11-11

All 46 known CVE vulnerabilities affecting gpac with full Chinese analysis, references, and POCs where available.