Description
FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can craft an .mpd manifest declaring SegmentTemplate media="" so get_current_fragment() calls av_strireplace() with an empty search string, consuming CPU indefinitely.
Published: 2026-10-08
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

FFmpeg up to version 9.0.2 includes a flaw (CWE-835) in the DASH demuxer that allows a crafted .mpd manifest with an empty SegmentTemplate media attribute to trigger an infinite loop. The loop occurs when get_current_fragment() calls a string replacement routine with a zero‑length search string, causing the demuxer to consume CPU cycles indefinitely. This denial of service can be triggered simply by providing the malformed manifest to FFmpeg's media parsing function.

Affected Systems

The vulnerability impacts the FFmpeg project, specifically all releases up through 9.0.2. Deployments of FFmpeg that use the DASH demuxer for processing media should consider this risk if they accept external manifest files. Earlier versions before 9.0.2 are also affected, as the code path is unchanged.

Risk and Exploitability

The CVSS score is 5.7, indicating moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, suggesting that routine exploitation is not currently observed. The likely attack vector involves providing a malicious manifest to an instance of FFmpeg that processes DASH streams, which can occur as a remote or local attack by an adversary who controls media input. With no known mitigations beyond updating, an attacker can exhaust CPU resources and potentially disrupt service availability.

Generated by OpenCVE AI on October 8, 2026 at 18:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to version 9.0.3 or later, where the DASH demuxer fix removes the empty string replacement logic.
  • If an upgrade is not immediately feasible, disable or bypass the DASH demuxer for untrusted manifests, or validate that the SegmentTemplate media attribute is non‑empty before passing the file to FFmpeg.
  • Apply system‑level resource limits or sandboxing to contain any accidental or malicious infinite loops, ensuring that a single FFmpeg process cannot consume all CPU or memory.

Generated by OpenCVE AI on October 8, 2026 at 18:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can craft an .mpd manifest declaring SegmentTemplate media="" so get_current_fragment() calls av_strireplace() with an empty search string, consuming CPU indefinitely.
Title FFmpeg through 9.0.2 DASH Demuxer Infinite Loop via Empty SegmentTemplate Media
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-835
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T16:03:10.865Z

Reserved: 2026-10-08T15:11:28.211Z

Link: CVE-2026-107677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:05.430

Modified: 2026-10-08T16:17:05.430

Link: CVE-2026-107677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')