Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FFmpeg — Vulnerabilities & Security Advisories 29

Browse all 29 CVE security advisories affecting FFmpeg. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FFMPEG serves as a fundamental multimedia framework for processing audio, video, and other digital content across countless applications and systems. Historically, it has been susceptible to remote code execution vulnerabilities through crafted media files, often due to buffer overflows in parsing components. Other common issues include denial-of-service conditions and memory corruption flaws. While no single major incident stands out, its widespread deployment means vulnerabilities in FFMPEG can impact numerous products and services. The 11 recorded CVEs reflect ongoing security challenges in handling untrusted media data, requiring careful input validation and sandboxing when processing files from untrusted sources.

Top products by FFmpeg: FFMPEG MPEG-DASH
CVE IDTitleCVSSSeverityPublished
CVE-2026-66041 FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter — FFmpegCWE-787 8.8 High2026-07-24
CVE-2026-66040 FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder — FFmpegCWE-122 8.8 High2026-07-24
CVE-2026-66039 FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File — FFmpegCWE-190 8.8 High2026-07-24
CVE-2026-66038 FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c — FFmpegCWE-908 6.5 Medium2026-07-24
CVE-2026-66037 FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() — FFmpegCWE-770 6.5 Medium2026-07-24
CVE-2026-66036 FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter — FFmpegCWE-122 8.8 High2026-07-24
CVE-2026-65706 FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing — FFmpegCWE-787 7.8 High2026-07-23
CVE-2026-65705 FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame() — FFmpegCWE-787 7.8 High2026-07-23
CVE-2026-65704 FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder — FFmpegCWE-787 7.8 High2026-07-23
CVE-2026-65703 FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder — FFmpegCWE-787 7.8 High2026-07-23
CVE-2026-64835 FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder — FFmpegCWE-787 8.8 High2026-07-22
CVE-2026-64834 FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer — FFmpegCWE-835 7.5 High2026-07-22
CVE-2026-64833 FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c — FFmpegCWE-125 7.1 High2026-07-22
CVE-2026-64832 FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c — FFmpegCWE-415 8.8 High2026-07-22
CVE-2026-64831 FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder — FFmpegCWE-121 8.8 High2026-07-22
CVE-2026-64830 FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer — FFmpegCWE-122 8.8 High2026-07-22
CVE-2026-58049 FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta() — FFmpegCWE-787 8.6 High2026-06-28
CVE-2026-8461 Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder — FFmpegCWE-787 8.8 High2026-06-18
CVE-2026-40962 FFmpeg 安全漏洞 — FFmpegCWE-190 4.9 Medium2026-04-16
CVE-2025-59734 Heap-buffer-overflow write in FFmpeg SANM process_ftch — FFmpegCWE-416 7.8AIHighAI2025-10-06
CVE-2025-59733 Heap-buffer-overflow write in FFmpeg EXR dwa_uncompress — FFmpegCWE-787 7.1AIHighAI2025-10-06
CVE-2025-59732 Heap-buffer-overflow write in FFmpeg EXR dwa_uncompress — FFmpegCWE-787 7.1AIHighAI2025-10-06
CVE-2025-59731 Heap-buffer-overflow write in FFmpeg EXR dwa_uncompress — FFmpegCWE-787 7.8AIHighAI2025-10-06
CVE-2025-59730 Heap-buffer-overflow write in FFmpeg SANM decoding due to lack of bounds-checking in old_codec48 — FFmpegCWE-787 9.8AICriticalAI2025-10-06
CVE-2025-59729 Heap-buffer-overflow read in FFmpeg DHAV get_duration — FFmpegCWE-787 3.3AILowAI2025-10-06
CVE-2025-59728 Heap-buffer-overflow write in FFmpeg MDASH resolve_content_path — MPEG-DASHCWE-787 9.8AICriticalAI2025-10-06
CVE-2025-9951 Remote code execution via Heap Buffer Overflow in FFmpeg JPEG2000 — FFmpegCWE-122 8.8AIHighAI2025-09-09
CVE-2025-0518 Unchecked sscanf return value which leads to memory data leak — FFmpegCWE-252 6.5 -2025-01-16
CVE-2022-2566 Heap-memory write in FFMPEG — FFMPEGCWE-122 9.0 Critical2022-09-23

This page lists every published CVE security advisory associated with FFmpeg. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.