Description
FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.
Published: 2026-10-08
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Credential Theft and Data Tampering
Action: Patch Immediately
AI Analysis

Impact

The vulnerability lies in the libssh-based SFTP protocol handler of FFmpeg versions up to 9.0.2, where host key verification is omitted. This omission means an attacker can perform a man‑in‑the‑middle attack, impersonating an SFTP server and capturing passwords supplied in SFTP URLs, serving counterfeit media, or retrieving uploaded output. The flaw exposes sensitive authentication data and allows unauthorized modification of data streams, effectively compromising confidentiality, integrity, and availability of media transfers.

Affected Systems

Vendor: FFmpeg. Product: FFmpeg. Versions affected include all builds through 9.0.2 as identified by the CPE string cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*.*

Risk and Exploitability

The CVSS score of 6.0 indicates a moderate severity level. No EPSS score was published, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Nonetheless, the attack surface is remote, requiring network access to an SFTP endpoint. Attackers who control the network path or can spoof DNS/ARP could exploit the flaw to intercept credentials or tamper with media payloads. The lack of host key verification removes crucial authentication checks, making incident response more difficult and potentially leading to further compromise if the intercepted credentials are used against downstream systems.

Generated by OpenCVE AI on October 8, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to a version newer than 9.0.2 or apply a vendor‑supplied patch that re‑introduces host key verification in the libssh SFTP handler.
  • Avoid using SFTP URLs with embedded credentials; instead, use secure authentication mechanisms and external key verification.
  • If immediate upgrade is not possible, configure network-level controls to block unauthorized SFTP traffic and monitor for anomalous SFTP connections to detect potential impersonation attempts.

Generated by OpenCVE AI on October 8, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.
Title FFmpeg through 9.0.2 Missing SSH Host Key Verification in sftp Protocol
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-322
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T18:00:38.446Z

Reserved: 2026-10-08T15:11:27.695Z

Link: CVE-2026-107675

cve-icon Vulnrichment

Updated: 2026-10-08T18:00:35.480Z

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:05.070

Modified: 2026-10-08T18:17:25.603

Link: CVE-2026-107675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses
  • CWE-322

    Key Exchange without Entity Authentication