FFmpeg 8.0.x DoS via parse_playlist in Duration Parser (pre8.1, pre9.0)
CVE-2026-90816 Published on September 14, 2026

FFmpeg Duration hlsproto.c parse_playlist denial of service
A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Type

Improper Resource Shutdown or Release

The program does not release or incorrectly releases a resource before it is made available for re-use. When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.


Products Associated with CVE-2026-90816

Want to know whenever a new CVE is published for FFmpeg? stack.watch will email you.