PT-2026-108036 · FFmpeg · Ffmpeg

·

CVE-2026-107675

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107675

Affected Products

Ffmpeg