CVE-2025-55650: Use-After-Fe in GPAC/MP4Box via gf_svg_node_del on crafted MP4 file processed with -svg

Published Jun 13, 2026
·
Updated

A heap use-after-free in the gfnodegettag function (scenegraph/basescenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Affected Software

2 affected components
Gpac MP4Box=2.4
Gpac GPAC<26.02.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove GPAC MP4Box v2.4 from your environment.

    Uninstall or avoid using GPAC MP4Box v2.4 until the vendor releases a security fix.

  2. Configuration

    Do not process untrusted MP4 files using MP4Box's -svg option; disable or avoid using the -svg feature until an official patch is available.

    GPAC MP4Box svg processing (-svg) = disabled / avoid using -svg
  3. Compensating control

    Process MP4 files in an isolated/sandboxed environment and restrict processing to trusted inputs. Block or quarantine uploads of untrusted MP4 files before they are processed by MP4Box.

Event History

Jun 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-55650?

The severity of CVE-2025-55650 is rated as medium with a score of 5.5.

2

What is the impact of CVE-2025-55650?

CVE-2025-55650 can lead to a Denial of Service (DoS) condition when a crafted MP4 file is processed.

3

How can I fix CVE-2025-55650?

To fix CVE-2025-55650, upgrade to a patched version of GPAC MP4Box that addresses this vulnerability.

4

What does CVE-2025-55650 exploit?

CVE-2025-55650 exploits a heap use-after-free vulnerability in the gf_node_get_tag function.

5

Is CVE-2025-55650 specific to certain software?

Yes, CVE-2025-55650 specifically affects GPAC MP4Box version 2.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203