{"id":"CVE-2026-107698","summary":"FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling","details":"FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services.","modified":"2026-10-09T07:06:54.292045101Z","published":"2026-10-08T17:30:28.683Z","database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107698.json","cna_assigner":"VulnCheck"},"references":[{"type":"WEB","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg"},{"type":"FIX","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22292"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107698.json"},{"type":"PACKAGE","url":"https://github.com/FFmpeg/FFmpeg"},{"type":"ARTICLE","url":"https://github.com/FFmpeg/FFmpeg/blob/n7.1.3/libavformat/rtsp.c#L2016"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/2326bc5f69c9"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/7c011995e394"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/ea9e85e54981b8402368d0f21648836d6738f1b1"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/f9aa8729bce1"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107698"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ffmpeg-before-7.1.4-and-8.0.2-ssrf-via-rtsp-redirect-handling"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"0"},{"fixed":"9abe92e3af7fa7becc8f7f742b1457b4c28220a6"},{"introduced":"140fd653aed8cad774f991ba083e2d01e86420c7"},{"fixed":"1c28c14f778a167936fe5e026e07b17223db39e5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"7.1.4"},{"introduced":"8.0"},{"fixed":"8.0.2"}],"source":"AFFECTED_FIELD"}}],"versions":["n7.1.3","n8.0.1","n7.1.2","n8.0","n7.1.1","n7.1","n7.1-dev","n6.2-dev","n6.1-dev","n5.2-dev","n5.1-dev","n4.5-dev","n4.4-dev","n4.3-dev","n4.2-dev","n4.1-dev","n3.5-dev","n3.4-dev","n3.3-dev","n3.2-dev","n3.1-dev","n2.9-dev","n2.8-dev","n2.7-dev","n2.6-dev","n2.5-dev","n2.4-dev","n2.3-dev","n2.2-dev","n2.0","n2.1-dev","n1.3-dev","n1.2-dev","n1.1-dev","n0.12-dev","n0.11-dev","n0.8","N"],"database_specific":{"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/ffmpeg/ffmpeg/commit/9abe92e3af7fa7becc8f7f742b1457b4c28220a6","target":{"file":"libavcodec/av1dec.c"},"deprecated":false,"digest":{"line_hashes":["310817141143537001029248579461295725276","208740041288583414147788132174592785369","46652776748372446914969201569469239493","267110340055762423129087277871349164572","307787047317858608879848576581970506090","315971375483810601273072689973927279813","145885355285875860957627039304224366116","113158543499858080897054177049509703606","37648303293323836412190903734402350782","284761500889657112652644749323980439136","266223691151276250049006818402084180503","272444542744745912533759191210667333869","92418624320850172745235155592234248789"],"threshold":0.9},"id":"CVE-2026-107698-1e2323e2"},{"source":"https://github.com/ffmpeg/ffmpeg/commit/9abe92e3af7fa7becc8f7f742b1457b4c28220a6","target":{"file":"libavcodec/av1dec.c","function":"read_global_param"},"deprecated":false,"digest":{"function_hash":"245869084628522575763408943802280487497","length":1234},"id":"CVE-2026-107698-dc3e9fb9","signature_type":"Function","signature_version":"v1"}],"vanir_signatures_modified":"2026-10-09T07:06:54Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107698.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}