CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107660

MEDIUMCVSS 4.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-iss

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107660 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107660

MEDIUMCVSS 4.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-iss

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]