FFmpeg 9.0.2 及之前版本中存在一个因缺少主机密钥验证而导致的漏洞,该漏洞位于基于 libssh 的 SFTP 协议处理程序中,允许网络攻击者伪装成 SFTP 服务器。实施中间人攻击(Man-in-the-Middle)、DNS 欺骗或 ARP 欺骗的攻击者可以截取通过 SFTP URL 提供的密码,提供伪造的媒体文件,或接收上传的输出内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107695 | 6.5 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Infinite Loop via Self-Referencing Playlist |
| CVE-2026-107696 | 6.5 MEDIUM | FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c |
| CVE-2026-107698 | 5.4 MEDIUM | FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling |
| CVE-2026-107660 | 4.8 MEDIUM | FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts |
| CVE-2026-107677 | 4.7 MEDIUM | FFmpeg through 9.0.2 DASH Demuxer Infinite Loop via Empty SegmentTemplate Media |
| CVE-2026-107678 | 4.7 MEDIUM | FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes |
| CVE-2026-107697 | 4.3 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Security Check Bypass via parse_playlist() |
| CVE-2026-107676 | 3.3 LOW | FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer |
No comments yet