CVE-2025-60473: NULL Pointer Defence in GPAC/MP4Box via gf_filter_in_pant_chain on crafted MPEG-2 TS file
Published Jun 24, 2026
·Updated
A NULL pointer dereference in the gffilterinparentchain function (/filtercore/filterpid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
Affected Software
2 affected components
Gpac MP4Box<26.02.0
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 25, 2026
Data Sourced
via NVD·12:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60473?
The severity of CVE-2025-60473 is medium with a CVSS score of 5.5.
2
How does CVE-2025-60473 affect GPAC/MP4Box?
CVE-2025-60473 allows attackers to cause a Denial of Service (DoS) by exploiting a NULL pointer dereference in the gf_filter_in_parent_chain function.
3
How do I fix CVE-2025-60473?
You can fix CVE-2025-60473 by applying the available patch provided by the GPAC Project.
4
What is the impact of CVE-2025-60473?
The impact of CVE-2025-60473 is primarily a Denial of Service which can disrupt the functioning of applications relying on GPAC/MP4Box.
5
When was CVE-2025-60473 published?
CVE-2025-60473 was published on June 24, 2026.