CVE WATCH / VULNERABILITY DETAIL
CVE-2026-107660
MEDIUMCVSS 4.8NVD feed
Published 8 October 2026 · tracked since 9 October 2026
Description
FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-iss
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107294 MEDIUM 6.5
- CVE-2026-107295 HIGH 7.6
- CVE-2026-107296 LOW 3.7
- CVE-2026-107297 MEDIUM 5.9
- CVE-2026-107290 MEDIUM 6.5
- CVE-2026-107291
- CVE-2026-107292 MEDIUM 6.4
- CVE-2026-107293
- CVE-2026-105436 HIGH 8.8
- CVE-2026-104077 HIGH 7.8