๐Ÿ” CVE Alert

CVE-2026-107678

MEDIUM 4.7

FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.

CWE CWE-674
Vendor ffmpeg
Product ffmpeg
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for ffmpeg ffmpeg

Be the first to know when new medium vulnerabilities affecting ffmpeg ffmpeg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

FFmpeg / FFmpeg
0 โ‰ค 9.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24593 github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/encryption_info.c#L219-L231 github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/mov.c#L8070 ffmpeg.org: https://ffmpeg.org/ vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-stack-exhaustion-via-recursive-free-of-pssh-boxes

Credits

Joshua Rogers (AISLE Research)