CVE-2025-70305: Medium severity Gpac GPAC vulnerability
Published Jan 15, 2026
·Updated
A stack overflow in the dmxsaf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.
Affected Software
2 affected components
Gpac GPAC
Gpac GPAC=2.4.0
Event History
Jan 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70305?
CVE-2025-70305 is classified as a high severity vulnerability due to its potential to cause a Denial of Service.
2
How do I fix CVE-2025-70305?
To mitigate CVE-2025-70305, upgrade GPAC to version 2.4.1 or later, where the vulnerability has been addressed.
3
What does CVE-2025-70305 affect?
CVE-2025-70305 affects GPAC version 2.4.0, specifically targeting the dmx_saf function.
4
What kind of attack can be executed using CVE-2025-70305?
CVE-2025-70305 allows attackers to execute a Denial of Service (DoS) attack via a specially crafted .saf file.
5
What software is vulnerable to CVE-2025-70305?
The specific version of the GPAC software that is vulnerable to CVE-2025-70305 is version 2.4.0.