Home / CVEs we hold for Gpac CVEs we hold for Gpac Records whose assigning authority named Gpac as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9572 GPAC MP4Box media.c Media_GetSample memory leak n/a GPAC CVE-2026-9567 GPAC MP4Box isom_intern.c MergeFragment null pointer dereference n/a GPAC CVE-2026-93331 GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds n/a GPAC CVE-2026-92475 GPAC downloader.c wait_for_header_and_parse out-of-bounds n/a GPAC CVE-2026-92474 GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free n/a GPAC CVE-2026-92473 GPAC BIFS commands.c gf_sg_command_del use after free n/a GPAC CVE-2026-92472 GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free n/a GPAC CVE-2026-92399 GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow n/a GPAC CVE-2026-91091 GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruption n/a GPAC CVE-2026-91090 GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow n/a GPAC CVE-2026-91089 GPAC base_scenegraph.c gf_node_get_name_and_id use after free n/a GPAC CVE-2026-91088 GPAC URL url.c gf_url_concatenate_ex heap-based overflow n/a GPAC CVE-2026-91087 GPAC Compositor media_object.c gf_mo_get_od_id use after free n/a GPAC CVE-2026-91086 GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflow n/a GPAC CVE-2026-90827 GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free n/a GPAC CVE-2026-90826 GPAC MP4Box base_scenegraph.c gf_node_del out-of-bounds n/a GPAC CVE-2026-90825 GPAC MP4Box base_scenegraph.c gf_node_unregister use after free n/a GPAC CVE-2026-90824 GPAC MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflow n/a GPAC CVE-2026-90794 GPAC MP4Box vrml_tools.c gf_sg_script_load use after free n/a GPAC CVE-2026-90793 GPAC MP4Box base_scenegraph.c gf_node_get_name use after free n/a GPAC CVE-2026-90792 GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference n/a GPAC CVE-2026-90791 GPAC MP4Box base_scenegraph.c gf_node_unregister use after free n/a GPAC CVE-2026-90687 GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free n/a GPAC CVE-2026-90686 GPAC MP4Box loader_bt.c gf_bt_report memory corruption n/a GPAC CVE-2026-90685 GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion n/a GPAC CVE-2026-90684 GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion n/a GPAC CVE-2026-90683 GPAC MP4Box base_scenegraph.c gf_node_unregister assertion n/a GPAC CVE-2026-90613 GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion n/a GPAC CVE-2026-90612 GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion n/a GPAC CVE-2026-90611 GPAC MP4Box loader_xmt.c xmt_parse_element assertion n/a GPAC CVE-2026-90610 GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read n/a GPAC CVE-2026-90609 GPAC MP4Box vrml_tools.c null pointer dereference n/a GPAC CVE-2026-90577 GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow n/a GPAC CVE-2026-90576 GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference n/a GPAC CVE-2026-90573 GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference n/a GPAC CVE-2026-8124 GPAC box_code_base.c sidx_box_read allocation of resources n/a GPAC CVE-2026-7135 GPAC MP4Box box_code_base.c elng_box_read out-of-bounds n/a GPAC CVE-2026-4185 GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow n/a GPAC CVE-2026-4016 GPAC SVG Parser load_svg.c svgin_process out-of-bounds write n/a GPAC CVE-2026-4015 GPAC TeXML File load_text.c txtin_process_texml stack-based overflow n/a GPAC CVE-2026-33144 GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing) gpac CVE-2026-27821 GPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer Overflow gpac CVE-2026-15185 GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds n/a GPAC CVE-2026-14801 GPAC TeXML File load_text.c txtin_probe_duration divide by zero n/a GPAC CVE-2026-14790 GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference n/a GPAC CVE-2026-1418 GPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds write n/a GPAC CVE-2026-1417 GPAC filedump.c dump_isom_rtp null pointer dereference n/a GPAC CVE-2026-1416 GPAC filedump.c DumpMovieInfo null pointer dereference n/a GPAC CVE-2026-1415 GPAC media_export.c gf_media_export_webvtt_metadata null pointer dereference n/a GPAC CVE-2025-7797 GPAC dash_client.c gf_dash_download_init_segment null pointer dereference n/a GPAC CVE-2025-15668 GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow n/a GPAC CVE-2025-15667 GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free n/a GPAC CVE-2024-6064 GPAC MP4Box loader_xmt.c xmt_node_end use after free n/a GPAC CVE-2024-6063 GPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereference n/a GPAC CVE-2024-6062 GPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereference n/a GPAC CVE-2024-6061 GPAC MP4Box isoffin_read.c isoffin_process infinite loop n/a GPAC CVE-2023-4722 Integer Overflow or Wraparound in gpac/gpac gpac/gpac CVE-2023-4720 Floating Point Comparison with Incorrect Operator in gpac/gpac gpac/gpac CVE-2023-1449 GPAC av_parsers.c gf_av1_reset_state double free n/a GPAC CVE-2023-1448 GPAC mpegts.c gf_m2ts_process_sdt heap-based overflow n/a GPAC CVE-2023-0841 GPAC reframe_mp3.c mp3_dmx_process heap-based overflow n/a GPAC CVE-2022-2454 Integer Overflow or Wraparound in gpac/gpac gpac/gpac CVE-2022-1172 Null Pointer Dereference Caused Segmentation Fault in gpac/gpac gpac/gpac CVE-2022-1035 Segmentation Fault caused by MP4Box -lsr in gpac/gpac gpac/gpac 139 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.