CVE-2026-107676
Received Received - Intake

Uninitialized Memory Disclosure in FFmpeg

Vulnerability report for CVE-2026-107676, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FFmpeg FFmpeg 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FFmpeg through version 9.0.2 has an uninitialized memory disclosure vulnerability in the function av_dynamic_hdr_plus_to_t35(). When the tone_mapping_flag is set to 0, up to three payload bytes remain uninitialized. Attackers can exploit this by providing specially crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata, causing remuxing or transcoding operations to write leaked process memory into output files.

Detection Guidance

Detecting this vulnerability requires checking FFmpeg versions and analyzing media files for uninitialized memory in metadata. Use 'ffmpeg -version' to verify if your version is affected. Inspect Matroska or HEVC/AV1 files with tools like 'ffprobe' for suspicious T.35 or SEI metadata blocks.

Impact Analysis

This vulnerability could allow attackers to access sensitive information stored in memory by causing FFmpeg to include uninitialized memory contents in output files. This may lead to exposure of confidential data, such as credentials or personal information, depending on the context in which FFmpeg is used.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of personal or sensitive data, potentially violating GDPR, HIPAA, or other privacy regulations. Organizations using affected FFmpeg versions may face compliance risks due to potential data leaks in processed media files.

Mitigation Strategies

Update FFmpeg to the latest version beyond 9.0.2. Avoid processing untrusted media files with FFmpeg until patched. Monitor output files for unexpected data in metadata blocks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107676. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart