FFmpeg 8.0.x DoS via parse_playlist in Duration Parser (pre8.1, pre9.0)
CVE-2026-90816 Published on September 14, 2026
FFmpeg Duration hlsproto.c parse_playlist denial of service
A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Type
Improper Resource Shutdown or Release
The program does not release or incorrectly releases a resource before it is made available for re-use. When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.
Products Associated with CVE-2026-90816
Want to know whenever a new CVE is published for FFmpeg? stack.watch will email you.