---
id: CVE-2026-56711
title: >-
  VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety
  vulnerability reachable when processing crafted media
summary: >-
  VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety
  vulnerability reachable when processing crafted media. Exploitation requires
  user interaction and may result in application termination or code execution
  with the pri…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
  - CWE-787
vendor: VideoLAN
product: VLC media player
affected:
  - vlc_media_player >= 3.0.0 <= 3.0.23
published: '2026-09-09'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:07.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56711'
references:
  - url: 'https://github.com/videolan/vlc'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00148
epssPercentile: 0.03347
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T17:10:00.632054Z'
ingestedAt: '2026-09-14T15:23:07.463Z'
---

## Overview

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
