CVE-2026-107697: Ffmpeg
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions restrictions when opening child playlists. Attackers can supply a crafted master playlist whose child playlists use disallowed protocols or non-multimedia local files, making parse_playlist() open resources the HLS security policy should block.
Affected products
- Ffmpeg Ffmpeg: before 8.1.3 (fixed in 8.1.3)
Published 2026-10-08. Last modified 2026-10-08.