VulnSea

FFmpeg vulnerabilities

CVEs whose affected-version data names the FFmpeg package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-90815Medium· 6.3PoC
1w ago

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-o…

TwilightRed Hat · FFmpegEPSS 0.24%via NVD
CVE-2026-90816Medium· 4.3PoC
1w ago

A vulnerability was found in FFmpeg 8.0.x

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial…

TwilightRed Hat · FFmpegEPSS 0.35%via NVD
CVE-2026-52297Low· 2.9⚖ disputed
1w ago

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

SunlitFFmpeg · FFmpegEPSS 0.12%via NVD
CVE-2026-52296Low· 2.9⚖ disputed
1w ago

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

SunlitFFmpeg · FFmpegEPSS 0.16%via NVD
CVE-2026-52295Low· 2.9
3w ago

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.

SunlitFFmpeg · FFmpegEPSS 0.12%via NVD
FFmpeg vulnerabilities (CVEs) · VulnSea