PT-2026-97343 · Unknown · Streamlink
CVE-2026-92164
·
Published
2026-09-23
·
Updated
2026-10-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Streamlink versions prior to 8.6.0
Description
Streamlink is a CLI utility that pipes video streams from various services into a video player. The
HTTPSession component mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting cross-protocol redirects. A remote server controlling an HTTP or HTTPS URL can return a redirect to a local file URL, causing HTTPSession to read the local file and return its contents to the response consumer. This bypasses direct file URL checks for HLS and DASH content because the manifest contains a network URL and the scheme transition occurs during fetch handling. This flaw affects every request made through HTTPSession, potentially placing local file contents into the stream output during a segment fetch.Recommendations
Update to version 8.6.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Streamlink