Description
FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services. | |
| Title | FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling | |
| First Time appeared |
Ffmpeg
Ffmpeg ffmpeg |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ffmpeg
Ffmpeg ffmpeg |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T17:51:31.797Z
Reserved: 2026-10-08T16:51:40.447Z
Link: CVE-2026-107698
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-918
Server-Side Request Forgery (SSRF)