CVE-2026-107677

medium

Description

FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can craft an .mpd manifest declaring SegmentTemplate media="" so get_current_fragment() calls av_strireplace() with an empty search string, consuming CPU indefinitely.

References

https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-dash-demuxer-infinite-loop-via-empty-segmenttemplate-media

https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/avstring.c#L230-L238

https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/dashdec.c#L1726

https://ffmpeg.org/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95082

https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592

https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ed27bfcbbbc0872c0195eaf4dd2c0c93b9f1778e

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 4.7

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity: Medium

CVSS v4

Base Score: 5.7

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00114