CVE-2026-107695
Last modified
CVE-2026-107695 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into opening a crafted self-referencing playlist that endlessly adds variants in hls_read_header(), causing unbounded CPU and I/O consumption..
Description
FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into opening a crafted self-referencing playlist that endlessly adds variants in hls_read_header(), causing unbounded CPU and I/O consumption.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FFmpeg | FFmpeg | < 8.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107695?
How severe is CVE-2026-107695?
How do I fix CVE-2026-107695?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107675FFmpeg through 9.0.2 contains a missing host key verificatio…5.9
- CVE-2026-107676FFmpeg through 9.0.2 contains an uninitialized memory disclo…3.3
- CVE-2026-107677FFmpeg through 9.0.2 contains a denial of service vulnerabil…4.7
- CVE-2026-107678FFmpeg through 9.0.2 contains a stack exhaustion vulnerabili…4.7
- CVE-2026-10768Missing Authorization vulnerability in Drupal LocalGov Workf…9.8
- CVE-2026-10769Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-107696FFmpeg through 9.0.2 contains an infinite loop vulnerability…6.5
- CVE-2026-107697FFmpeg before 8.1.3 contains a protection mechanism failure …4.3
- CVE-2026-107698FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server…5.4
- CVE-2026-107699ppt2png through 0.0.6 contains an OS command injection vulne…9.8
- CVE-2026-10770Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-107700dot-access 0.0.3 through 1.0.0 contains a code injection vul…9.8
Are you affected by CVE-2026-107695?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
