Out-of-bounds Write Vulnerability in FFmpeg's Libavcodec Library
CVE-2026-8461

8.8HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
18 June 2026

Badges

📈 Score: 919👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-8461?

CVE-2026-8461 is a severe security vulnerability identified in the FFmpeg software, specifically within its libavcodec library, utilized for encoding and decoding audio and video formats. This vulnerability arises from an out-of-bounds write error in the MagicYUV decoder, potentially allowing attackers to manipulate memory in an uncontrolled manner. If exploited, this vulnerability can lead to denial-of-service (DoS) conditions, rendering systems unavailable, and in certain instances, it may enable remote code execution, allowing attackers to execute arbitrary code on affected systems. Such repercussions can significantly disrupt operations, compromise system integrity, and expose sensitive data to unauthorized users.

The issue is present in all versions of FFmpeg prior to 8.1.2, highlighting the urgency for users to ensure they are running a patched version to mitigate this security risk. Given that FFmpeg is widely used in various multimedia applications, the impact of the vulnerability can be extensive across diverse industries reliant on video and audio processing.

Potential impact of CVE-2026-8461

  1. Denial-of-Service Attacks: Exploiting CVE-2026-8461 can lead to service disruptions, making systems that rely on FFmpeg unavailable. This can adversely affect any organization using FFmpeg-based applications, leading to losses in productivity and potential damage to reputation.

  2. Remote Code Execution: The vulnerability has the potential to allow remote attackers to execute arbitrary code. This could facilitate unauthorized access to systems and sensitive information, leading to data breaches, further system compromise, and the possibility of deploying additional malware.

  3. Operational Disruptions: With the widespread use of FFmpeg in media applications, any successful exploitation could disrupt critical workflows in sectors such as broadcasting, video streaming services, and content creation. This could result in significant operational setbacks and financial losses for affected organizations.

Affected Version(s)

FFmpeg 0 < 8.1.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service  condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.