CVE-2026-107697
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions restrictions when opening child playlists. Attackers can supply a crafted master playlist whose child playlists use disallowed protocols or non-multimedia local files, making parse_playlist() open resources the HLS security policy should block.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0032
Percentile
0,2th
Updated
EPSS Score Trend (Last 3 Days)
693
Protection Mechanism Failure
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Not Technology-Specific, ICS/OT
https://github.com/FFmpeg/FFmpeg
https://github.com/FFmpeg/FFmpeg/blob/n8.1.2/libavformat/hls.c#L834
https://github.com/FFmpeg/FFmpeg/commit/01044d04536e
https://github.com/FFmpeg/FFmpeg/commit/191715f0232c
https://github.com/FFmpeg/FFmpeg/commit/23602df9cd1b485c45ba6f533d3b85569de3f323
https://www.vulncheck.com/advisories/ffmpeg-before-8.1.3-hls-demuxer-security-c…