CVE-2026-107695
Received Received - Intake

Infinite Loop in FFmpeg HLS Demuxer

Vulnerability report for CVE-2026-107695, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into opening a crafted self-referencing playlist that endlessly adds variants in hls_read_header(), causing unbounded CPU and I/O consumption.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FFmpeg FFmpeg 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an infinite loop vulnerability in FFmpeg's HLS demuxer. It occurs when a crafted HLS playlist contains Master Playlist tags inside a Media Playlist. The parse_playlist function incorrectly processes these tags, causing hls_read_header to repeatedly add variants without exiting, leading to unbounded CPU and I/O consumption.

Detection Guidance

Monitor for processes consuming excessive CPU or I/O due to infinite loops in FFmpeg HLS parsing. Check logs for repeated playlist reloading or errors in avformat/hls.c. Use network traffic analysis to detect repeated requests to the same HLS playlist file.

Impact Analysis

This vulnerability can cause denial of service by consuming 100% CPU and I/O indefinitely. It affects server-side applications processing user-uploaded HLS content like video transcoding services or streaming servers. Exploitation requires no user interaction and can be triggered remotely.

Mitigation Strategies
  • Upgrade FFmpeg to version 8.1.3 or later to apply the official patch.
  • Block or sanitize untrusted HLS playlist files before processing them with FFmpeg.
  • Implement rate limiting or timeout mechanisms for playlist parsing operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107695. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart