Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168075 vulns · 37/41 feeds (7d)
← Back to list
6.1
CVE-2025-60465EXPLOITEDPATCHED
gpac project · mp4box

CVE-2025-60465: A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02

Description

A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

Affected Products

VendorProductVersions
gpac projectmp4boxn/a

References

  • https://github.com/gpac/gpac/issues/3283
  • https://github.com/gpac/gpac/commit/55b351bd078c950592544ab4c708a613c1725b9b
  • https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/34/34_gf_filter_pid_inst_swap_filter_core_filter_pid_c_633
  • https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/34/README.md
  • https://infosec.exchange/@sigdevel/116778494176930561

Related News (2 articles)

Tier C
oss-security23h ago
CVE-2025-60465: Use-After-Free in GPAC/MP4Box via gf_filter_pid_inst_swap on crafted MPEG-2 TS file
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2025-60465 | GPAC up to 26.1.x MP4Box filter_pid.c gf_filter_pid_inst_swap use after free (Issue 3283)
→ No new info (linked only)
CVSS 3.16.1 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
26.1.0
PublishedJun 25, 2026
Last enriched22h agov3
Tags
DoSUse-After-Free
Trending Score55
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2025-60474EXP
CVE-2025-60474: A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo
Trending: 67
HIGHCVE-2025-60467EXP
CVE-2025-60467: A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box
Trending: 60
HIGHCVE-2025-60464EXP
CVE-2025-60464: A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.
Trending: 59
MEDIUMCVE-2025-60466EXP
CVE-2025-60466: A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0
Trending: 55
MEDIUMCVE-2025-60473EXP
CVE-2025-60473: A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box
Trending: 55

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026
Updated: description, affectedVersions, severity, exploitAvailable, activelyExploited, patchAvailable
Jun 25, 2026
Updated: description, cweIds, cvssEstimate, tags
Jun 27, 2026
Actively Exploited
Jun 27, 2026
Exploit Available
Jun 27, 2026
Patch Available
Jun 27, 2026

Version History

v3
Last enriched 22h ago
v3Tier C22h ago

Updated description with more technical detail, added CWE-416, and changed CVSS score from 6.1 to 4.3.

descriptioncweIdscvssEstimatetags
via oss-security
v2Tier C2d ago

Updated vendor and product information, marked severity as CRITICAL, and noted that an exploit is available and the vulnerability is actively exploited.

descriptionaffectedVersionsseverityexploitAvailableactivelyExploitedpatchAvailable
via VulDB
v12d ago

Initial creation