---
id: CVE-2026-107696
title: >-
  FFmpeg through 9.0.2 contains an infinite loop vulnerability in
  ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects
  without any redirect limit
summary: >-
  FFmpeg through 9.0.2 contains an infinite loop vulnerability in
  ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects
  without any redirect limit. Attackers controlling an RTSP server can answer
  every request with a 302 …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-835
vendor: FFmpeg
product: FFmpeg
affected:
  - FFmpeg <= 9.0.2
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:04:38.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107696'
references:
  - url: 'https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24902'
    label: disclosure@vulncheck.com
  - url: 'https://gist.github.com/OxBat/648a0bd60c898f2ffb418e131ce26013'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/FFmpeg/FFmpeg'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/rtsp.c#L2225'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-infinite-loop-via-rtsp-redirect-handling-in-rtsp-c
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T17:56:11.736Z'
---

## Overview

FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
