Denial of Service Vulnerability in FFmpeg DASH Demuxer
CVE-2026-107677

5.7MEDIUM

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107677?

A denial of service vulnerability has been identified in FFmpeg's DASH demuxer, allowing attackers to create an infinite loop condition. By supplying a specially crafted .mpd manifest with an empty SegmentTemplate media URL, the function get_current_fragment() continuously calls av_strireplace() with an empty search string. This results in excessive CPU consumption, potentially crippling the performance of the system running the affected version of FFmpeg. Users are advised to update to the latest version that resolves this issue.

Affected Version(s)

FFmpeg 0 <= 9.0.2

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers (AISLE Research)
.