---
id: CVE-2026-90816
title: A vulnerability was found in FFmpeg 8.0.x
summary: >-
  A vulnerability was found in FFmpeg 8.0.x. This affects the function
  parse_playlist of the file libavformat/hlsproto.c of the component Duration
  Parser. Performing a manipulation of the argument duration/target_duration
  results in denial…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
  - CWE-835
product: FFmpeg
affected:
  - FFmpeg 8.0.*
published: '2026-09-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T20:19:20.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90816'
references:
  - url: 'https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/64fafd63f0b4'
    label: cna@vuldb.com
  - url: 'https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21492'
    label: cna@vuldb.com
  - url: 'https://ffmpeg.org/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90816'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/922626'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403318'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403318/cti'
    label: cna@vuldb.com
  - url: 'https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21492'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90816.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90816'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533346'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90816'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90816'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T19:31:13.282602Z'
epss: 0.0058
epssPercentile: 0.45304
ingestedAt: '2026-09-14T20:14:21.148Z'
vendor: Red Hat
scores:
  nvd: 4.3
  vendor: 5.5
---

## Overview

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat OpenShift AI (RHOAI) · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90816.json)
