{"id":"UBUNTU-CVE-2026-44353","details":"Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. This vulnerability is fixed in 8.4.0.","modified":"2026-06-03T13:41:47.832763996Z","published":"2026-05-27T17:16:00Z","upstream":["CVE-2026-44353"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-44353"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-44353"},{"type":"REPORT","url":"https://github.com/streamlink/streamlink/security/advisories/GHSA-hgqw-6m45-hw5f"}],"affected":[{"package":{"name":"streamlink","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/streamlink?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.0+dfsg.2-3","0.10.0+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"livestreamer","binary_version":"1.12.2+streamlink+0.10.0+dfsg-1"},{"binary_name":"python3-streamlink","binary_version":"0.10.0+dfsg-1"},{"binary_version":"0.10.0+dfsg-1","binary_name":"streamlink"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44353.json"}},{"package":{"name":"streamlink","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/streamlink?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.1+dfsg-1","1.2.0+dfsg-1","1.3.0+dfsg-1","1.3.1+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-streamlink","binary_version":"1.3.1+dfsg-1"},{"binary_name":"streamlink","binary_version":"1.3.1+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44353.json"}},{"package":{"name":"streamlink","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/streamlink?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.0-1","2.4.0-1","3.0.3-1","3.1.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-streamlink","binary_version":"3.1.1-1"},{"binary_version":"3.1.1-1","binary_name":"streamlink"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44353.json"}},{"package":{"name":"streamlink","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/streamlink?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.0.1-1","6.3.0-1","6.3.1-1","6.3.1-2","6.4.2-1","6.5.0-1","6.5.1-1","6.6.1-1","6.6.2-1"],"ecosystem_specific":{"binaries":[{"binary_version":"6.6.2-1","binary_name":"python3-streamlink"},{"binary_name":"streamlink","binary_version":"6.6.2-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44353.json"}},{"package":{"name":"streamlink","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/streamlink?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.1.3-1","7.3.0-1","7.3.0-2","7.5.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"7.5.0-1","binary_name":"python3-streamlink"},{"binary_name":"streamlink","binary_version":"7.5.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44353.json"}},{"package":{"name":"streamlink","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/streamlink?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.5.0-1","7.6.0-2","8.1.0-1","8.1.2-1","8.2.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-streamlink","binary_version":"8.2.0-1"},{"binary_name":"streamlink","binary_version":"8.2.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44353.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}