YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0002

Register entry

FFmpeg MPEG-DASH resolve_content_path: heap overflow write, found by Google Big Sleep

CVE
CVE-2025-59728
Project
FFmpeg
Component
MPEG-DASH resolve_content_path
Finder
Google Big Sleep
Autonomy
agent finds and reproduces; a human expert reviews before reporting
Evidence tier
Credits array names the finder
Assigner
Google
Severity
8.7 High (CVSS 4.0)
Bounty
None published
Confidence
CONFIRMED

What happened

One of seven FFmpeg records Google filed as CNA on 6 October 2025 with Big Sleep as finder, affecting 7.1.1 up to 8.0. The seven span 21 July to 20 August 2025 by datePublic, the signature of a campaign pointed at one codebase.

Credit as recorded: finder: "Google Big Sleep". Date basis: datePublic.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026