CVE-2026-107698
FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services.
| CWE | CWE-918 |
| Vendor | ffmpeg |
| Product | ffmpeg |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for ffmpeg ffmpeg
Be the first to know when new medium vulnerabilities affecting ffmpeg ffmpeg are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
FFmpeg / FFmpeg
0 < 7.1.4 8.0 < 8.0.2
References
github.com: https://github.com/FFmpeg/FFmpeg/commit/ea9e85e54981b8402368d0f21648836d6738f1b1 github.com: https://github.com/FFmpeg/FFmpeg/commit/2326bc5f69c9 github.com: https://github.com/FFmpeg/FFmpeg/commit/7c011995e394 github.com: https://github.com/FFmpeg/FFmpeg/commit/f9aa8729bce1 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22292 github.com: https://github.com/FFmpeg/FFmpeg/blob/n7.1.3/libavformat/rtsp.c#L2016 github.com: https://github.com/FFmpeg/FFmpeg vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-before-7.1.4-and-8.0.2-ssrf-via-rtsp-redirect-handling
Credits
BapToutatis