CVE-2026-107695
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Media Playlists. Attackers can trick victims into opening a crafted self-referencing playlist that endlessly adds variants in hls_read_header(), causing unbounded CPU and I/O consumption.