PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-60473 GPAC CVE debrief

CVE-2025-60473 is a MEDIUM severity vulnerability in GPAC Project MP4Box before 26.02.0. A NULL pointer dereference in the gf_filter_in_parent_chain function allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. The vulnerability was published on June 25, 2026, and last modified on June 29, 2026. The Common Vulnerability Scoring System (CVSS) score is 5.5. This vulnerability is exploitable via a crafted MP4 file. The attack vector is Local, and the attack complexity is Low.

Vendor
GPAC
Product
MP4Box
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-25
Original CVE updated
2026-06-29
Advisory published
2026-06-25
Advisory updated
2026-06-29

Who should care

GPAC Project users, developers, and maintainers should be aware of this vulnerability. Additionally, security teams and administrators responsible for systems that use GPAC Project MP4Box should prioritize patching this vulnerability to prevent potential Denial of Service (DoS) attacks.

Technical summary

The vulnerability is caused by a NULL pointer dereference in the gf_filter_in_parent_chain function located in the /filter_core/filter_pid.c file of GPAC Project MP4Box before 26.02.0. An attacker can exploit this vulnerability by supplying a crafted MP4 file, which can lead to a Denial of Service (DoS) condition. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The attack vector is Local, and the attack complexity is Low.

Defensive priority

Patching this vulnerability is of medium priority. Administrators should apply the patch as soon as possible to prevent potential Denial of Service (DoS) attacks.

Recommended defensive actions

  • Apply the official patch: https://github.com/gpac/gpac/commit/b8d80b44718de10b101e1d7fc17c84d69feb092e
  • Update GPAC Project MP4Box to version 26.02.0 or later
  • Restrict access to MP4Box to trusted users and systems
  • Monitor systems for unusual activity and potential DoS attacks
  • Consider implementing compensating controls, such as network segmentation and traffic filtering

Evidence notes

The vulnerability was published on June 25, 2026, and last modified on June 29, 2026. The CVE record and NVD detail pages provide additional information about the vulnerability. The GPAC Project has released a patch for this vulnerability.

Official resources

This article is AI-assisted and based on the supplied source corpus.