https://seclists.org/oss-sec/2026/q2/904: CVE-2025-55652: Heap-based Buffer Overflow in GPAC/MP4Box via gf_isom_vp_config_new on crafted MP4 with malformed VP codec configuration
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<74fecde32cd477ab097f3e6db55a32b259f3313d
Frequently Asked Questions
1
What is the severity of CVE-2025-55652?
CVE-2025-55652 has a CVSS 3.1 score of 4.3, indicating a medium severity level.
2
How do I fix CVE-2025-55652?
To mitigate CVE-2025-55652, you should update GPAC (MP4Box) to a version that includes the fix after commit 74fecde32cd477ab097f3e6db55a32b259f3313d.
3
What types of systems are affected by CVE-2025-55652?
CVE-2025-55652 affects all versions of GPAC (MP4Box) prior to the fix commit.
4
What is the nature of the vulnerability CVE-2025-55652?
CVE-2025-55652 is a heap-based buffer overflow vulnerability that arises from processing malformed VP codec configuration in crafted MP4 files.
5
Who reported CVE-2025-55652?
CVE-2025-55652 was reported by a security researcher using the alias sigdevel.