An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
https://github.com/thystra/jellyfin-security-images
https://github.com/the-artist111/NeuralReaper
https://github.com/ray-goldman/ffmpeg-jellyfix
https://github.com/0xBlackash/CVE-2026-8461
https://github.com/HORKimhab/CVE-2026-8461
https://github.com/patissierMongs/advisory-platform
https://github.com/Unclecheng-li/poc-lab
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.json
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37878
https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159
https://bugzilla.redhat.com/show_bug.cgi?id=2490308
Published: 2026-06-18
Updated: 2026-07-23
Named Vulnerability: PixelSmashNamed Vulnerability: GHSA-qff7-4q6c-m8h6
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00346