aom-main vulnerabilities
CVEs whose affected-version data names the aom-main package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-56211High· 7.1A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation
A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted vide…
CVE-2026-56210High· 7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation
A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the co…
CVE-2026-56209High· 7.1An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer i…
CVE-2026-56208High· 7.6A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when …