CVE-2026-107697 — FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions rest…
Description
FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions restrictions when opening child playlists. Attackers can supply a crafted master playlist whose child playlists use disallowed protocols or non-multimedia local files, making parse_playlist() open resources the HLS security policy should block.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
Passive
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/FFmpeg/FFmpeg
- advisory[email protected]https://github.com/FFmpeg/FFmpeg/blob/n8.1.2/libavformat/hls.c#L834
- advisory[email protected]https://github.com/FFmpeg/FFmpeg/commit/01044d04536e
- advisory[email protected]https://github.com/FFmpeg/FFmpeg/commit/191715f0232c
- advisory[email protected]https://github.com/FFmpeg/FFmpeg/commit/23602df9cd1b485c45ba6f533d3b85569de3f323
- advisory[email protected]https://www.vulncheck.com/advisories/ffmpeg-before-8.1.3-hls-demuxer-security-check-bypass-via-parse-playlist
Related threats
same CWE or vendorCVE-2026-16916 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …
CVE-2026-16916 · 2h ago
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 4h ago
Coraza: jsDecode Off-by-One in Octal Escape Handling Enables WAF Bypass
CVE-2026-104774 · 5h ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
CVE-2026-107226 · 6h ago
PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow
CVE-2026-61437 · 6h ago
CVE-2026-76283 — Protection Mechanism Failure.
CVE-2026-76283 · 1d ago