Impact
FFmpeg versions prior to 8.1.3 and any 9.x series before 9.0.2 contain an improper certificate validation flaw in the libavformat/tls_mbedtls.c component. The flaw causes the tls_open() function to skip hostname checks for IP-address hosts, allowing an attacker to intercept and modify traffic that uses HTTPS, RTMPS, or generic TLS connections to IP literal URLs. The certificate presented may be any trusted CA‑issued certificate, so the attacker can provide a valid certificate while still impersonating a different host, leading to plaintext or manipulated streams.
Affected Systems
All FFmpeg releases before 8.1.3 and before 9.0.2 in the 9.x line are impacted. The vulnerability applies to all builds using the mbedTLS transport layer, regardless of platform, affecting anyone who connects to services via IP literals over TLS‑enabled protocols.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the EPSS score is not available, suggesting current exploit probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, and no publicly known exploit is documented. However, the attack vector is network‑based, requiring only the ability to establish a connection to an IP literal URL using HTTPS, RTMPS, or TLS. Once the connection is established, the attacker can supply a CA‑signed certificate that bypasses hostname verification and read or alter the stream.
OpenCVE Enrichment