CVE-2026-107677
Received Received - Intake

FFmpeg DASH Demuxer Infinite Loop via Empty SegmentTemplate

Vulnerability report for CVE-2026-107677, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can craft an .mpd manifest declaring SegmentTemplate media="" so get_current_fragment() calls av_strireplace() with an empty search string, consuming CPU indefinitely.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FFmpeg FFmpeg 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in FFmpeg through version 9.0.2. It occurs in the DASH demuxer when an attacker supplies an empty SegmentTemplate media URL in an .mpd manifest. This causes the get_current_fragment() function to call av_strireplace() with an empty search string, leading to an infinite loop that consumes CPU resources indefinitely.

Detection Guidance

To detect this vulnerability, inspect FFmpeg logs for excessive CPU usage during media processing. Check for .mpd files with SegmentTemplate media="" in DASH streams. Monitor system resources for abnormal consumption during media playback or conversion tasks.

Impact Analysis

This vulnerability can cause system slowdowns or crashes due to excessive CPU usage. If exploited, it may disrupt media processing tasks, leading to service unavailability or degraded performance on affected systems running vulnerable versions of FFmpeg.

Compliance Impact

This vulnerability primarily causes a denial of service by consuming excessive CPU resources through an infinite loop. It does not directly impact data confidentiality or integrity, which are key concerns for GDPR and HIPAA compliance. However, prolonged system unavailability due to crashes could indirectly affect compliance by disrupting processing of personal or health data.

Mitigation Strategies

Update FFmpeg to the latest version beyond 9.0.2. Block or sanitize .mpd files with empty SegmentTemplate media attributes. Restrict untrusted media file processing to prevent crafted manifests from reaching vulnerable systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107677. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart