Infinite Loop Vulnerability in FFmpeg HLS Demuxer
CVE-2026-107695
Key Information:
Badges
What is CVE-2026-107695?
FFmpeg versions prior to 8.1.3 contain a vulnerability in the HLS demuxer that can be exploited by remote attackers to create a denial of service condition. This occurs when the parse_playlist() function improperly handles Master Playlist tags embedded in Media Playlists. Attackers may deceive users into opening a specially crafted self-referencing playlist, which can repeatedly add variants in the hls_read_header() function. This results in unbounded CPU and I/O consumption, effectively exhausting system resources and causing service disruption.
Affected Version(s)
FFmpeg 0 < 8.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
