Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into opening a crafted self-referencing playlist that endlessly adds variants in hls_read_header(), causing unbounded CPU and I/O consumption. | |
| Title | FFmpeg before 8.1.3 HLS Demuxer Infinite Loop via Self-Referencing Playlist | |
| First Time appeared |
Ffmpeg
Ffmpeg ffmpeg |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ffmpeg
Ffmpeg ffmpeg |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T17:30:26.951Z
Reserved: 2026-10-08T16:51:39.543Z
Link: CVE-2026-107695
No data.
No data.
No data.
OpenCVE Enrichment
No data.