Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107675

MEDIUM NVD
CVSS Score 5.9
Severity MEDIUM
Published Oct 08, 2026
Vendor unknown

Description

FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.

References