PT-2026-97343 · Unknown · Streamlink

CVE-2026-92164

·

Published

2026-09-23

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Streamlink versions prior to 8.6.0
Description Streamlink is a CLI utility that pipes video streams from various services into a video player. The HTTPSession component mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting cross-protocol redirects. A remote server controlling an HTTP or HTTPS URL can return a redirect to a local file URL, causing HTTPSession to read the local file and return its contents to the response consumer. This bypasses direct file URL checks for HLS and DASH content because the manifest contains a network URL and the scheme transition occurs during fetch handling. This flaw affects every request made through HTTPSession, potentially placing local file contents into the stream output during a segment fetch.
Recommendations Update to version 8.6.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92164
GHSA-VF2X-4V53-PM7V
PYSEC-2026-4172

Affected Products

Streamlink