CVE-2025-59728: CWE-787 Out-of-bounds Write in FFmpeg MPEG-DASH
CVE-2025-59728 is a high-severity vulnerability in FFmpeg's MPEG-DASH handling where an out-of-bounds write occurs due to improper buffer management when appending a '/' character to a string buffer. This results in a NUL-byte being written one byte past the allocated buffer end. The issue affects versions prior to 8.0. No known exploits are reported in the wild as of the publication date.
AI Analysis
Technical Summary
This vulnerability arises in FFmpeg's MPEG-DASH manifest processing when calculating the content path. The function xmlNodeGetContent returns a buffer allocated exactly to the string length. If the buffer's last character is not '/', the code attempts to append '/' and a NUL terminator in-place, causing a two-byte write starting at the last valid byte. This leads to an out-of-bounds NUL-byte write one byte beyond the allocated buffer, classified as CWE-787 (Out-of-bounds Write). The vulnerability is present in FFmpeg versions 7.1.1 and the specified commit, with a recommendation to upgrade to version 8.0 or later.
Potential Impact
The out-of-bounds write can lead to memory corruption, which may cause application crashes or potentially enable an attacker with limited privileges to escalate impact due to the high CVSS vector components (high vector and impact complexity). However, no known exploits are reported in the wild at this time.
Mitigation Recommendations
Upgrade FFmpeg to version 8.0 or later, where this vulnerability has been addressed. Since no official patch links are provided, users should verify the upgrade path through the FFmpeg project releases. Patch status is not explicitly confirmed beyond the upgrade recommendation; therefore, check the vendor advisory for the latest remediation guidance.
CVE-2025-59728: CWE-787 Out-of-bounds Write in FFmpeg MPEG-DASH
Description
CVE-2025-59728 is a high-severity vulnerability in FFmpeg's MPEG-DASH handling where an out-of-bounds write occurs due to improper buffer management when appending a '/' character to a string buffer. This results in a NUL-byte being written one byte past the allocated buffer end. The issue affects versions prior to 8.0. No known exploits are reported in the wild as of the publication date.
CVSS v4.0
Score 8.7high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises in FFmpeg's MPEG-DASH manifest processing when calculating the content path. The function xmlNodeGetContent returns a buffer allocated exactly to the string length. If the buffer's last character is not '/', the code attempts to append '/' and a NUL terminator in-place, causing a two-byte write starting at the last valid byte. This leads to an out-of-bounds NUL-byte write one byte beyond the allocated buffer, classified as CWE-787 (Out-of-bounds Write). The vulnerability is present in FFmpeg versions 7.1.1 and the specified commit, with a recommendation to upgrade to version 8.0 or later.
Potential Impact
The out-of-bounds write can lead to memory corruption, which may cause application crashes or potentially enable an attacker with limited privileges to escalate impact due to the high CVSS vector components (high vector and impact complexity). However, no known exploits are reported in the wild at this time.
Mitigation Recommendations
Upgrade FFmpeg to version 8.0 or later, where this vulnerability has been addressed. Since no official patch links are provided, users should verify the upgrade path through the FFmpeg project releases. Patch status is not explicitly confirmed beyond the upgrade recommendation; therefore, check the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- Date Reserved
- 2025-09-19T08:11:37.549Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68e382204a42da91e7586492
Added to database: 10/06/2025, 08:47:28 UTC
Last enriched: 06/03/2026, 21:23:50 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 488
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.