在 FFmpeg 8.1.3 之前的版本以及 9.x 版本中 9.0.2 之前的版本中,libavformat/tls_mbedtls.c 文件的 tls_open() 函数存在证书验证不当的漏洞,该漏洞会跳过对 IP 地址主机的 hostname 检查。网络攻击者可以利用任何由受信任的证书颁发机构(CA)签发的证书,截获针对 IP 地址字面量(IP-literal)URL 的 HTTPS、RTMPS 或 TLS 连接,从而读取并篡改数据流。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107695 | 6.5 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Infinite Loop via Self-Referencing Playlist |
| CVE-2026-107696 | 6.5 MEDIUM | FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c |
| CVE-2026-107675 | 5.9 MEDIUM | FFmpeg through 9.0.2 Missing SSH Host Key Verification in sftp Protocol |
| CVE-2026-107698 | 5.4 MEDIUM | FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling |
| CVE-2026-107677 | 4.7 MEDIUM | FFmpeg through 9.0.2 DASH Demuxer Infinite Loop via Empty SegmentTemplate Media |
| CVE-2026-107678 | 4.7 MEDIUM | FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes |
| CVE-2026-107697 | 4.3 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Security Check Bypass via parse_playlist() |
| CVE-2026-107676 | 3.3 LOW | FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer |
No comments yet