CVE-2026-107696
Received Received - Intake

FFmpeg RTSP Redirect Infinite Loop Vulnerability

Vulnerability report for CVE-2026-107696, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
FFmpeg FFmpeg 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an infinite loop flaw in FFmpeg versions up to 9.0.2. It occurs in the RTSP protocol handling function ff_rtmp_connect(). When an attacker controls an RTSP server, they can send endless 302 redirect responses pointing back to themselves or another server. This forces FFmpeg to repeatedly reconnect, consuming excessive CPU resources.

Detection Guidance

To detect this vulnerability, monitor for unusual CPU usage spikes from ffmpeg processes. Check for repeated RTSP connection attempts or infinite loops in network logs. Use tools like 'top' or 'htop' to identify high CPU usage by ffmpeg. Inspect network traffic for excessive RTSP 302 redirects using 'tcpdump' or Wireshark.

Impact Analysis

If you use FFmpeg to process RTSP streams, this flaw could cause your system to experience high CPU usage, leading to performance degradation or crashes. Attackers could exploit this to disrupt services relying on FFmpeg for media processing.

Mitigation Strategies

Immediately update FFmpeg to the latest version that patches this issue. If updating is not possible, restrict network access to RTSP servers or disable RTSP support in FFmpeg. Implement rate limiting on RTSP connections to prevent infinite loops.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107696. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart