High severity8.1NVD Advisory· Published Aug 7, 2025· Updated May 12, 2026
CVE-2025-47219
CVE-2025-47219
Description
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.
Affected products
1- GStreamer/GStreamerdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0003.mdnvdExploitThird Party Advisory
- gstreamer.freedesktop.org/security/nvdVendor Advisory
- cert-portal.siemens.com/productcert/html/ssa-032379.htmlnvd
News mentions
1- Siemens SIMATICCISA Alerts