PT-2026-108112 · FFmpeg · Ffmpeg

·

CVE-2026-107696

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff rtsp connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107696

Affected Products

Ffmpeg