


Perceptive Security
SOC/SIEM Consultancy

An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.
Published:
14 January 2026 at 23:00:00
Alert date:
15 January 2026 at 18:11:37
Source:
nvd.nist.gov
Web Technologies
A vulnerability in GPAC v2.4.0's GSF demuxer filter component allows attackers to trigger an out-of-bounds read condition. The flaw can be exploited through specially crafted .gsf files to cause a Denial of Service attack. This affects the media processing capabilities of the GPAC multimedia framework. The vulnerability has been assigned CVE-2025-70308 and proof-of-concept code is publicly available.
Technical details
Mitigation steps:
Affected products:
GPAC
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-70308
https://github.com/zakkanijia/POC/blob/main/gpac_gsf/GPAC_gsf.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
