CVE-2025-70307: High severity Gpac GPAC vulnerability
Published Jan 15, 2026
·Updated
A stack overflow in the dumpttxtsample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
Affected Software
2 affected components
Gpac GPAC
Gpac GPAC=2.4.0
Event History
Jan 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70307?
CVE-2025-70307 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2025-70307?
To fix CVE-2025-70307, update to the latest version of GPAC that addresses this vulnerability.
3
What impact does CVE-2025-70307 have on systems using GPAC?
CVE-2025-70307 can lead to a stack overflow, causing a potential Denial of Service on affected systems.
4
Which version of GPAC is affected by CVE-2025-70307?
CVE-2025-70307 affects GPAC version 2.4.0.
5
How can an attacker exploit CVE-2025-70307?
An attacker can exploit CVE-2025-70307 by sending a crafted packet to trigger the stack overflow in the dump_ttxt_sample function.