CVE-2026-107675: Ffmpeg

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.

Affected products

  • Ffmpeg Ffmpeg: up to and including 9.0.2

Published 2026-10-08. Last modified 2026-10-08.