PatchSiren cyber security CVE debrief
CVE-2025-60473 GPAC CVE debrief
CVE-2025-60473 is a MEDIUM severity vulnerability in GPAC Project MP4Box before 26.02.0. A NULL pointer dereference in the gf_filter_in_parent_chain function allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. The vulnerability was published on June 25, 2026, and last modified on June 29, 2026. The Common Vulnerability Scoring System (CVSS) score is 5.5. This vulnerability is exploitable via a crafted MP4 file. The attack vector is Local, and the attack complexity is Low.
- Vendor
- GPAC
- Product
- MP4Box
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-25
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-25
- Advisory updated
- 2026-06-29
Who should care
GPAC Project users, developers, and maintainers should be aware of this vulnerability. Additionally, security teams and administrators responsible for systems that use GPAC Project MP4Box should prioritize patching this vulnerability to prevent potential Denial of Service (DoS) attacks.
Technical summary
The vulnerability is caused by a NULL pointer dereference in the gf_filter_in_parent_chain function located in the /filter_core/filter_pid.c file of GPAC Project MP4Box before 26.02.0. An attacker can exploit this vulnerability by supplying a crafted MP4 file, which can lead to a Denial of Service (DoS) condition. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The attack vector is Local, and the attack complexity is Low.
Defensive priority
Patching this vulnerability is of medium priority. Administrators should apply the patch as soon as possible to prevent potential Denial of Service (DoS) attacks.
Recommended defensive actions
- Apply the official patch: https://github.com/gpac/gpac/commit/b8d80b44718de10b101e1d7fc17c84d69feb092e
- Update GPAC Project MP4Box to version 26.02.0 or later
- Restrict access to MP4Box to trusted users and systems
- Monitor systems for unusual activity and potential DoS attacks
- Consider implementing compensating controls, such as network segmentation and traffic filtering
Evidence notes
The vulnerability was published on June 25, 2026, and last modified on June 29, 2026. The CVE record and NVD detail pages provide additional information about the vulnerability. The GPAC Project has released a patch for this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-60473 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-60473
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-60473 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-60473
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/gpac/gpac/commit/b8d80b44718de10b101e1d7fc17c84d69feb092e
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/gpac/gpac/issues/3285
[email protected] - Exploit, Issue Tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/36/36_gf_filter_in_parent_chain_filter_core_filter_pid_c_2145
[email protected] - Exploit
-
Source reference
Unverified legacy reference
URL: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/36/README.md
[email protected] - Exploit
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://infosec.exchange/@sigdevel/116780471059317580
[email protected] - Exploit, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.