Uncontrolled Resource Consumption in FFmpeg IAMF Demuxer
CVE-2026-66037

7.1HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66037?

FFmpeg versions up to 8.1.2 are affected by an uncontrolled resource consumption vulnerability in the IAMF demuxer. This flaw allows an unauthenticated attacker to exploit the system by providing a crafted count_label field that can trigger massive memory allocations. Specifically, the mix_presentation_obu() function does not properly validate the available data, leading to an amplification effect where a small input can result in multi-gigabyte memory usage. This issue may exhaust system memory, potentially resulting in an Out Of Memory (OOM) condition during format probing.

Affected Version(s)

FFmpeg 0 <= 8.1.2

FFmpeg 0 <= 8.1.2

FFmpeg 86708357d126af84c16f80d9c57335d1e8c845c5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Junge (vurlo)
.