Tools AI-Found Vulnerability Register aifv-0002
Register entry
FFmpeg MPEG-DASH resolve_content_path: heap overflow write, found by Google Big Sleep
- CVE
- CVE-2025-59728
- Project
- FFmpeg
- Component
- MPEG-DASH resolve_content_path
- Finder
- Google Big Sleep
- Autonomy
- agent finds and reproduces; a human expert reviews before reporting
- Evidence tier
- Credits array names the finder
- Assigner
- Severity
- 8.7 High (CVSS 4.0)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.
Credit as recorded: finder: "Google Big Sleep". Date basis: datePublic.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
On YFarmX
- Reference pageyfarmx.com/ai/security/big-sleep/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026