Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

FFmpeg before 8.1 allows malicious media files to crash or execute code

JLSEC-2026-652
Summary

A security issue in FFmpeg's media handling could allow attackers to create malicious media files that can cause FFmpeg to crash or potentially execute unauthorized code. This affects users who process or play media files with FFmpeg. To stay secure, update to FFmpeg version 8.1 or later.

What to do
  • Update ffmpeg_jll to version 8.1.0+0.
  • Update ffmpeg_nogpl_jll to version 8.1.0+0.
  • Update ffplay_jll to version 8.1.2+0.
Affected software
Ecosystem VendorProductAffected versions
Julia ffmpeg_jll < 8.1.0+0
Fix: upgrade to 8.1.0+0
Julia ffmpeg_nogpl_jll < 8.1.0+0
Fix: upgrade to 8.1.0+0
Julia ffplay_jll < 8.1.2+0
Fix: upgrade to 8.1.2+0
Original title
FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common...
Original description
FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.
osv CVSS3.1 4.9
Published: 26 Jun 2026 · Updated: 18 Jul 2026 · First seen: 26 Jun 2026