PatchSiren cyber security CVE debrief
CVE-2025-60473 GPAC CVE debrief
CVE-2025-60473 is a MEDIUM severity vulnerability in GPAC Project MP4Box before 26.02.0. A NULL pointer dereference in the gf_filter_in_parent_chain function allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. The vulnerability was published on June 25, 2026, and last modified on June 29, 2026. The Common Vulnerability Scoring System (CVSS) score is 5.5. This vulnerability is exploitable via a crafted MP4 file. The attack vector is Local, and the attack complexity is Low.
- Vendor
- GPAC
- Product
- MP4Box
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-25
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-25
- Advisory updated
- 2026-06-29
Who should care
GPAC Project users, developers, and maintainers should be aware of this vulnerability. Additionally, security teams and administrators responsible for systems that use GPAC Project MP4Box should prioritize patching this vulnerability to prevent potential Denial of Service (DoS) attacks.
Technical summary
The vulnerability is caused by a NULL pointer dereference in the gf_filter_in_parent_chain function located in the /filter_core/filter_pid.c file of GPAC Project MP4Box before 26.02.0. An attacker can exploit this vulnerability by supplying a crafted MP4 file, which can lead to a Denial of Service (DoS) condition. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The attack vector is Local, and the attack complexity is Low.
Defensive priority
Patching this vulnerability is of medium priority. Administrators should apply the patch as soon as possible to prevent potential Denial of Service (DoS) attacks.
Recommended defensive actions
- Apply the official patch: https://github.com/gpac/gpac/commit/b8d80b44718de10b101e1d7fc17c84d69feb092e
- Update GPAC Project MP4Box to version 26.02.0 or later
- Restrict access to MP4Box to trusted users and systems
- Monitor systems for unusual activity and potential DoS attacks
- Consider implementing compensating controls, such as network segmentation and traffic filtering
Evidence notes
The vulnerability was published on June 25, 2026, and last modified on June 29, 2026. The CVE record and NVD detail pages provide additional information about the vulnerability. The GPAC Project has released a patch for this vulnerability.
Official resources
-
CVE-2025-60473 CVE record
CVE.org
-
CVE-2025-60473 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Source reference
[email protected] - Exploit, Issue Tracking
-
Source reference
[email protected] - Exploit
-
Source reference
[email protected] - Exploit
-
Mitigation or vendor reference
[email protected] - Exploit, Patch, Third Party Advisory
-
Mitigation or vendor reference
af854a3a-2127-422b-91ae-364da2661108 - Exploit, Mailing List, Third Party Advisory
This article is AI-assisted and based on the supplied source corpus.