CVE-2026-90816

MEDIUM Status: Awaiting Analysis

CVSS Scores

CVSS v3.x Base Score
4.3
MEDIUM
CVSS v2 Base Score
5.0
MEDIUM

Description

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.

Published
September 14, 2026 8:17 PM
Last Modified
September 14, 2026 8:53 PM
Source
[email protected]

Weaknesses (CWE)

CWE-404

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.