Technology · Gpac
Gpac MP4Box vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in Gpac MP4Box: 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-90827, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 0
- Exploited in the wild
- 0
About Gpac MP4Box
MP4Box is a multimedia packager and command-line tool for the GPAC framework used for manipulating MPEG-4 files.
Latest Gpac MP4Box vulnerabilities
- CVE-2026-90827: GPAC MP4Box use-after-free in gf_node_deactivate_exlowCVSS 3.3EPSS 0.2%
- CVE-2026-90826: GPAC MP4Box out-of-bounds read in gf_node_dellowCVSS 2.8EPSS 0.2%
- CVE-2026-90794: GPAC MP4Box use-after-free in gf_sg_script_loadmediumCVSS 6.3EPSS 0.5%
- CVE-2026-90791: GPAC MP4Box use-after-free in gf_node_unregistermediumCVSS 6.3EPSS 0.5%
- CVE-2026-90686: GPAC MP4Box invalid read in gf_bt_report functionmediumCVSS 5.3EPSS 0.9%
- CVE-2026-90611: GPAC MP4Box reachable assertion in XMT parsinglowCVSS 3.3EPSS 0.2%
- CVE-2026-90578: GPAC MP4Box use-after-free in gf_list_countmediumCVSS 5.3EPSS 0.2%
- CVE-2025-55639: GPAC MP4Box NULL pointer dereference in gf_isom_add_track_kindinfoCVSS 5.5
- CVE-2025-55663: GPAC MP4Box segmentation violation in Track_SetStreamDescriptorinfo
- CVE-2025-55661: GPAC MP4Box heap buffer overflow in Opus audio stream parserinfoCVSS 0
- CVE-2025-55660: GPAC MP4Box stack overflow in gf_opus_read_lengthinfo
- CVE-2025-55652: GPAC MP4Box heap buffer overflow in gf_isom_vp_config_newinfo
- CVE-2025-55650: GPAC MP4Box heap use-after-free in gf_node_get_taginfo
- CVE-2025-55649: GPAC MP4Box NULL pointer dereference in gf_media_map_esdinfoCVSS 5.5
- CVE-2025-55648: GPAC MP4Box heap buffer overflow in gf_opus_parse_packet_headerinfo
- CVE-2025-55647: GPAC MP4Box Out-of-Memory in mp4_mux_cenc_insert_psshinfoCVSS 5.5
- CVE-2025-55645: GPAC MP4Box heap buffer overflow in gf_cenc_set_psshinfo
- CVE-2025-55644: GPAC MP4Box heap use-after-free in gf_node_get_taginfo
- CVE-2025-55643: GPAC MP4Box NULL pointer dereference in TrackWriterinfoCVSS 5.5
- CVE-2025-55642: GPAC MP4Box floating point exception in avidmx_processinfo
- CVE-2025-55641: GPAC MP4Box NULL pointer dereference in gf_isom_copy_sample_infoinfo
- CVE-2025-55659: GPAC MP4Box NULL pointer dereference in ctts_box_writeinfoCVSS 5.5
- CVE-2025-55658: GPAC MP4Box floating point exception in gf_opus_parse_packet_headerinfoCVSS 5.5
- CVE-2025-55657: GPAC MP4Box NULL pointer dereference in gf_odf_vvc_cfg_write_bsinfo
- CVE-2025-55651: GPAC MP4Box NULL pointer dereference in gf_isom_get_user_data_countinfo
Most severe Gpac MP4Box vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-90794: GPAC MP4Box use-after-free in gf_sg_script_loadmediumCVSS 6.3EPSS 0.5%
- CVE-2026-90791: GPAC MP4Box use-after-free in gf_node_unregistermediumCVSS 6.3EPSS 0.5%
- CVE-2026-90686: GPAC MP4Box invalid read in gf_bt_report functionmediumCVSS 5.3EPSS 0.9%
- CVE-2026-90578: GPAC MP4Box use-after-free in gf_list_countmediumCVSS 5.3EPSS 0.2%
- CVE-2026-90827: GPAC MP4Box use-after-free in gf_node_deactivate_exlowCVSS 3.3EPSS 0.2%
- CVE-2026-90611: GPAC MP4Box reachable assertion in XMT parsinglowCVSS 3.3EPSS 0.2%
- CVE-2026-90826: GPAC MP4Box out-of-bounds read in gf_node_dellowCVSS 2.8EPSS 0.2%
- CVE-2025-55639: GPAC MP4Box NULL pointer dereference in gf_isom_add_track_kindinfoCVSS 5.5
- CVE-2025-55649: GPAC MP4Box NULL pointer dereference in gf_media_map_esdinfoCVSS 5.5
- CVE-2025-55647: GPAC MP4Box Out-of-Memory in mp4_mux_cenc_insert_psshinfoCVSS 5.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 6 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/mp4box.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gpac MP4Box vulnerabilities", https://junglewise.ai/threats/technologies/mp4box, 26 September 2026.