๐Ÿ” CVE Alert

CVE-2026-107676

LOW 3.3

FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.

CWE CWE-908
Vendor ffmpeg
Product ffmpeg
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for ffmpeg ffmpeg

Be the first to know when new low vulnerabilities affecting ffmpeg ffmpeg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

FFmpeg / FFmpeg
0 โ‰ค 9.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24590 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2c2f6e96e31795ae95a8f8323a493ffbc493111f github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/hdr_dynamic_metadata.c#L374-L385 ffmpeg.org: https://ffmpeg.org/ vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-uninitialized-memory-disclosure-via-hdr10-metadata-serializer

Credits

Joshua Rogers (AISLE Research)