CVE-2026-107660
FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts
CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th
FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-issued certificate to read and tamper with streams.
| CWE | CWE-297 |
| Vendor | ffmpeg |
| Product | ffmpeg |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for ffmpeg ffmpeg
Be the first to know when new medium vulnerabilities affecting ffmpeg ffmpeg are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
FFmpeg / FFmpeg
0 < 8.1.3 9.0 < 9.0.2
References
code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24383 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/57a2e704b4a6eda5d061b45aacde6b19c026bfc0 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d377212904a19fc740d721cbda0ba58fa3805a29 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/0cd2a70eacd510c2efed48b9fc177c7cb2bc549f github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.1/libavformat/tls_mbedtls.c#L676-L681 ffmpeg.org: https://ffmpeg.org/ vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-before-8.1.3-and-9-x-before-9.0.2-mbedtls-hostname-verification-bypass-for-ip-hosts
Credits
Joshua Rogers (AISLE Research)