Description
A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the parse_playlist function of FFmpeg 8.0.x allows an attacker to manipulate the duration/target_duration argument, causing a crash and resulting in a denial of service. The weakness is an improper use of input parameters that leads to resource exhaustion or application termination.

Affected Systems

The vulnerability affects the FFmpeg library, specifically versions 8.0.x. Upgrading to FFmpeg 8.1 or later, or to issue.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate severity. The EPSS score is < 1% (approximately 0.0035), but the attack can be performed remotely, making the risk contingent on exposure to untrusted inputs. The vulnerability is not listed in the CISA KEV catalog, implying no known large-scale exploitation to date.

Generated by OpenCVE AI on September 20, 2026 at 22:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to version 8.1 or newer, which includes the fix for parse_playlist
  • If an upgrade cannot be applied immediately, limit remote access to components that parse HLS playlists, or disable the duration parsing feature if the functionality is not required
  • Configure resource limits or implement fail‑over strategies to mitigate the impact of unexpected crashes caused by the vulnerable parser

Generated by OpenCVE AI on September 20, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.
Title FFmpeg Duration hlsproto.c parse_playlist denial of service
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-404
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T19:31:29.406Z

Reserved: 2026-09-13T16:32:04.243Z

Link: CVE-2026-90816

cve-icon Vulnrichment

Updated: 2026-09-15T19:31:23.814Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:17:03.123

Modified: 2026-09-15T20:19:20.400

Link: CVE-2026-90816

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T20:00:05Z

Links: CVE-2026-90816 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')