Changeflow GovPing Data Privacy & Cybersecurity FFmpeg Vulnerability Allows Denial of Service a...
Priority review Notice Added Final

FFmpeg Vulnerability Allows Denial of Service and Information Disclosure

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 16th, 2026
Detected March 17th, 2026
Email

Summary

CERT-Bund has issued a security advisory (WID-SEC-2026-0740) regarding a vulnerability in the FFmpeg RV60 video decoder. The vulnerability allows remote attackers to cause a Denial of Service or disclose information. Affected versions include Open Source ffmpeg <8.1, 8.0, and 8.0.1.

What changed

CERT-Bund has released a security advisory (WID-SEC-2026-0740) detailing a critical vulnerability in the FFmpeg RV60 video decoder. This vulnerability, with a CVSS Base Score of 7.1, can be exploited remotely by anonymous attackers to execute Denial of Service attacks or to disclose sensitive information. The advisory affects Open Source ffmpeg versions prior to 8.1, including 8.0 and 8.0.1, and impacts systems running Windows, UNIX, and other operating systems.

Organizations utilizing FFmpeg should immediately assess their exposure to this vulnerability. Mitigation measures are available, and it is recommended to update FFmpeg to a patched version as soon as possible to prevent potential exploitation. Failure to address this vulnerability could lead to service disruptions and potential data breaches, impacting system availability and confidentiality.

What to do next

  1. Update FFmpeg to a version that addresses the RV60 video decoder vulnerability.
  2. Assess systems running affected FFmpeg versions for potential exploitation.
  3. Review system logs for any signs of attempted or successful exploitation.

Source document (simplified)

[WID-SEC-2026-0740] ffmpeg (RV60 video decoder): Schwachstelle ermöglicht Denial of Service und die Offenlegung von Informationen CVSS Base Score 7.1 (hoch) CVSS Temporal Score 6.2 (mittel) Remoteangriff ja Datum 16.03.2026 Stand 17.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

Das FFmpeg-Projekt besteht aus freien Programmen und Bibliotheken, die es ermöglichen, digitales Video- und Audiomaterial aufzunehmen, zu konvertieren, zu streamen und abzuspielen. Zudem enthält es mit libavcodec eine Audio- und Video-Codec-Sammlung, die verschiedene Codecs zur Verfügung stellt.

Produkte

16.03.2026
- Open Source ffmpeg <8.1

  • Open Source ffmpeg 8.0

  • Open Source ffmpeg 8.0.1

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in ffmpeg ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 16th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Manufacturers Technology companies
Geographic scope
Germany

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Information Disclosure Denial of Service

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.