Description
FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-issued certificate to read and tamper with streams.
Published: 2026-10-08
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Man-in-the-Middle
Action: Apply patch
AI Analysis

Impact

FFmpeg versions prior to 8.1.3 and any 9.x series before 9.0.2 contain an improper certificate validation flaw in the libavformat/tls_mbedtls.c component. The flaw causes the tls_open() function to skip hostname checks for IP-address hosts, allowing an attacker to intercept and modify traffic that uses HTTPS, RTMPS, or generic TLS connections to IP literal URLs. The certificate presented may be any trusted CA‑issued certificate, so the attacker can provide a valid certificate while still impersonating a different host, leading to plaintext or manipulated streams.

Affected Systems

All FFmpeg releases before 8.1.3 and before 9.0.2 in the 9.x line are impacted. The vulnerability applies to all builds using the mbedTLS transport layer, regardless of platform, affecting anyone who connects to services via IP literals over TLS‑enabled protocols.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, and the EPSS score is not available, suggesting current exploit probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, and no publicly known exploit is documented. However, the attack vector is network‑based, requiring only the ability to establish a connection to an IP literal URL using HTTPS, RTMPS, or TLS. Once the connection is established, the attacker can supply a CA‑signed certificate that bypasses hostname verification and read or alter the stream.

Generated by OpenCVE AI on October 8, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to version 8.1.3 or later, and to 9.0.2 or later for the 9.x series.
  • If an upgrade cannot be performed immediately, avoid using IP literal URLs for TLS‑enabled protocols; use hostname‑based URLs whenever possible.
  • Implement application‑level certificate validation to enforce hostname checking if possible, and monitor network traffic for anomalous TLS connections.

Generated by OpenCVE AI on October 8, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-issued certificate to read and tamper with streams.
Title FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-297
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:25:50.450Z

Reserved: 2026-10-08T14:50:58.333Z

Link: CVE-2026-107660

cve-icon Vulnrichment

Updated: 2026-10-08T17:25:38.759Z

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:04.893

Modified: 2026-10-08T18:17:25.457

Link: CVE-2026-107660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch