Technology · Ffmpeg
FFmpeg vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 47 vulnerabilities in FFmpeg: 0 in the last 7 days and 38 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-90816, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 38
- Critical, all time
- 3
- Exploited in the wild
- 0
About FFmpeg
FFmpeg is a complete, cross-platform solution to record, convert and stream audio and video.
Latest FFmpeg vulnerabilities
- CVE-2026-90816: FFmpeg HLS protocol handler denial of service via duration parsingmediumCVSS 4.3EPSS 0.6%
- CVE-2026-90815: FFmpeg convolution filter out-of-bounds readmediumCVSS 6.3EPSS 0.4%
- CVE-2026-52297: FFmpeg out-of-bounds read in MOV parsinglowCVSS 2.9EPSS 0.2%
- CVE-2026-52296: FFmpeg out-of-bounds read in WMA extradata allocationlowCVSS 2.9EPSS 0.2%
- CVE-2026-30754: FFmpeg memory corruption in RTP H.264/HEVC encodinghighCVSS 8.8EPSS 0.5%
- CVE-2026-52295: FFmpeg out-of-bounds read in IAMF writer extradata handlinglowCVSS 2.9EPSS 0.2%
- CVE-2026-18393: FFmpeg heap buffer overflow in TDSC cursor decodermediumCVSS 5.4EPSS 0.3%
- CVE-2026-38350: FFmpeg libswscale integer overflow in output conversionhighCVSS 7.5EPSS 0.5%
- CVE-2026-38349: FFmpeg integer overflow in libswscale hScale16To19_chighCVSS 7.5EPSS 0.5%
- CVE-2026-38348: FFmpeg integer overflow in libswscale image scalinghighCVSS 7.5EPSS 0.5%
- CVE-2026-38347: FFmpeg heap overflow in alphablend functionhighCVSS 7.5EPSS 0.5%
- CVE-2026-38346: FFmpeg integer overflow in yuv2planeX_8_chighCVSS 7.5EPSS 0.5%
- CVE-2026-38345: FFmpeg division-by-zero in libswscale scaling context initializationmediumCVSS 6.5EPSS 0.4%
- CVE-2026-38344: FFmpeg NULL pointer dereference in libswscale video scalinghighCVSS 7.5EPSS 0.5%
- CVE-2026-38343: FFmpeg integer overflow in libavfilter/vf_scale.cmediumCVSS 6.5EPSS 0.4%
- CVE-2026-75147: FFmpeg out-of-bounds read in AV1 RTP packetizerhighCVSS 7.1EPSS 0.2%
- CVE-2026-75146: FFmpeg DASH demuxer out-of-bounds read in fragment indexinghighCVSS 8.1EPSS 0.5%
- CVE-2026-75145: FFmpeg AV1 RTP packetizer integer narrowing bypass in libavformatmediumCVSS 5.8EPSS 0.2%
- CVE-2026-75144: FFmpeg heap buffer overflow in VC-2/Dirac RTP packetizerhighCVSS 7.8EPSS 0.2%
- CVE-2026-75143: FFmpeg heap buffer overflow in RIST protocol readercriticalCVSS 9.8EPSS 0.7%
- CVE-2026-75142: FFmpeg stack buffer overflow in MPEG-PS muxerhighCVSS 7.8EPSS 0.2%
- CVE-2026-75141: FFmpeg heap buffer overflow in hvcC box writerhighCVSS 7.8EPSS 0.2%
- CVE-2026-66041: FFmpeg heap out-of-bounds write in vf_quirc filterhighCVSS 8.8
- CVE-2026-66040: FFmpeg heap out-of-bounds write in PNG and APNG encodershighCVSS 8.8
- CVE-2026-66039: FFmpeg signed integer overflow in MACE6 audio decoderhighCVSS 8.8
Most severe FFmpeg vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-22778: vLLM remote code execution via JPEG2000 heap overflow and ASLR bypasscriticalCVSS 9.8EPSS 3.8%
- CVE-2026-75143: FFmpeg heap buffer overflow in RIST protocol readercriticalCVSS 9.8EPSS 0.7%
- CVE-2016-6164: FFmpeg integer overflow in mov_build_index functioncriticalCVSS 9.8
- CVE-2026-30754: FFmpeg memory corruption in RTP H.264/HEVC encodinghighCVSS 8.8EPSS 0.5%
- CVE-2026-8461: FFmpeg libavcodec out-of-bounds write in MagicYUV decoderhighCVSS 8.8EPSS 0.4%
- CVE-2026-66041: FFmpeg heap out-of-bounds write in vf_quirc filterhighCVSS 8.8
- CVE-2026-66040: FFmpeg heap out-of-bounds write in PNG and APNG encodershighCVSS 8.8
- CVE-2026-66039: FFmpeg signed integer overflow in MACE6 audio decoderhighCVSS 8.8
- CVE-2026-66036: FFmpeg heap out-of-bounds write in vf_hqdn3d filterhighCVSS 8.8
- CVE-2026-64835: FFmpeg OOB memory access in ADX audio decoderhighCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 16 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 7 | 1 | |
| 24 Aug 2026 | 9 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/ffmpeg.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "FFmpeg vulnerabilities", https://junglewise.ai/threats/technologies/ffmpeg, 26 September 2026.