CVE-2025-55639Medium· 6.5▾ SunlitGPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
gpac < 26.02.0Upgrade past the affected range:
gpac 26.02.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90573Low· 3.3A vulnerability was identified in GPAC up to f1219cde
CVE-2026-90576Low· 3.3A security vulnerability has been detected in GPAC up to f1219cde
CVE-2026-90609Low· 3.3A vulnerability has been found in GPAC up to f1219cde
CVE-2026-90792Medium· 4.3A flaw has been found in GPAC up to f1219cde
CVE-2026-103227Medium· 6.3A weakness has been identified in GPAC up to 26.07.0
CVE-2026-93331High· 7.3A vulnerability was identified in GPAC 26.08-DEV