CVE-2026-107675
Received Received - Intake

Missing Host Key Verification in FFmpeg libssh SFTP

Vulnerability report for CVE-2026-107675, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FFmpeg FFmpeg 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-322 The product performs a key exchange with an actor without verifying the identity of that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FFmpeg through version 9.0.2 has a missing SSH host key verification vulnerability in its libssh-based SFTP protocol handler. This allows attackers to impersonate SFTP servers using man-in-the-middle, DNS, or ARP spoofing. The flaw enables capturing passwords from SFTP URLs, serving malicious media, or intercepting uploaded data.

Detection Guidance

To detect this vulnerability, check the FFmpeg version installed on your system. Run: ffmpeg -version. If the version is 9.0.2 or earlier, the system is vulnerable. Additionally, monitor network traffic for suspicious SFTP connections or man-in-the-middle attempts.

Impact Analysis

An attacker exploiting this could steal credentials entered in SFTP URLs, replace legitimate media files with malicious ones, or intercept sensitive data being uploaded. This could lead to unauthorized access, data breaches, or malware distribution through forged files.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using vulnerable FFmpeg versions may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Immediately update FFmpeg to a version later than 9.0.2. Disable SFTP protocol usage if not required. Implement network monitoring to detect spoofing attempts. Ensure SSH host key verification is enforced in all SFTP connections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107675. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart