Denial of Service Vulnerability in FFmpeg DASH Demuxer
CVE-2026-107677
5.7MEDIUM
What is CVE-2026-107677?
A denial of service vulnerability has been identified in FFmpeg's DASH demuxer, allowing attackers to create an infinite loop condition. By supplying a specially crafted .mpd manifest with an empty SegmentTemplate media URL, the function get_current_fragment() continuously calls av_strireplace() with an empty search string. This results in excessive CPU consumption, potentially crippling the performance of the system running the affected version of FFmpeg. Users are advised to update to the latest version that resolves this issue.
Affected Version(s)
FFmpeg 0 <= 9.0.2
