{"id":"CVE-2026-56711","title":"VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media","summary":"VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the pri…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-190","CWE-787"],"vendor":"VideoLAN","product":"VLC media player","affected":["vlc_media_player >= 3.0.0 <= 3.0.23"],"published":"2026-09-09","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:07.347","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56711","references":[{"url":"https://github.com/videolan/vlc","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00148,"epssPercentile":0.03347,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T17:10:00.632054Z"},"ingestedAt":"2026-09-14T15:23:07.463Z","slug":"CVE-2026-56711","body":"## Overview\n\nVLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}