FFmpeg 9.0.2 及之前版本在 libavformat/rtsp.c 的 ff_rtsp_connect() 函数中存在无限循环漏洞,该函数在处理 RTSP 3xx 重定向时未设置重定向次数限制。攻击者若控制 RTSP 服务器,可在每次请求中返回指向自身或另一台服务器的 302 重定向响应,从而导致反复重连,最终耗尽一个 CPU 核心资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107695 | 6.5 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Infinite Loop via Self-Referencing Playlist |
| CVE-2026-107675 | 5.9 MEDIUM | FFmpeg through 9.0.2 Missing SSH Host Key Verification in sftp Protocol |
| CVE-2026-107698 | 5.4 MEDIUM | FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling |
| CVE-2026-107660 | 4.8 MEDIUM | FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts |
| CVE-2026-107677 | 4.7 MEDIUM | FFmpeg through 9.0.2 DASH Demuxer Infinite Loop via Empty SegmentTemplate Media |
| CVE-2026-107678 | 4.7 MEDIUM | FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes |
| CVE-2026-107697 | 4.3 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Security Check Bypass via parse_playlist() |
| CVE-2026-107676 | 3.3 LOW | FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer |
No comments yet