๐Ÿ” CVE Alert

CVE-2026-107660

MEDIUM 4.8

FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-issued certificate to read and tamper with streams.

CWE CWE-297
Vendor ffmpeg
Product ffmpeg
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for ffmpeg ffmpeg

Be the first to know when new medium vulnerabilities affecting ffmpeg ffmpeg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

FFmpeg / FFmpeg
0 < 8.1.3 9.0 < 9.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24383 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/57a2e704b4a6eda5d061b45aacde6b19c026bfc0 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d377212904a19fc740d721cbda0ba58fa3805a29 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/0cd2a70eacd510c2efed48b9fc177c7cb2bc549f github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.1/libavformat/tls_mbedtls.c#L676-L681 ffmpeg.org: https://ffmpeg.org/ vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-before-8.1.3-and-9-x-before-9.0.2-mbedtls-hostname-verification-bypass-for-ip-hosts

Credits

Joshua Rogers (AISLE Research)