
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30997 is an out-of-bounds read vulnerability in FFmpeg's AV1 decoder that allows unauthenticated attackers to cause a Denial of Service (DoS) via crafted input. The flaw resides in the read_global_param() function within libavcodec/av1dec.c and affects FFmpeg version 8.0.1 and earlier. It was published on April 13, 2026, with a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (GitHub Advisory, NVD).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), occurring in the read_global_param() function of FFmpeg's AV1 decoder (libavcodec/av1dec.c). When processing a specially crafted AV1 video stream, the function reads memory beyond the intended buffer boundary, leading to a crash of the decoding process. The attack requires no authentication, no user interaction, and can be triggered remotely over a network by supplying a malicious AV1 stream to any application or service using FFmpeg for video processing (GitHub Advisory, NVD).
Successful exploitation results in a Denial of Service condition, crashing the FFmpeg process or any application that relies on FFmpeg for AV1 video decoding. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Services such as media transcoding pipelines, streaming servers, or video processing applications built on FFmpeg v8.0.1 or earlier are at risk of disruption if they process untrusted AV1 content (GitHub Advisory, NVD).
No confirmed in-the-wild exploitation has been observed, and no verified proof-of-concept exploit code is publicly available — a referenced Notion page was found to be a JavaScript placeholder with no actual exploit content (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.04–0.077%, placing it in the lower percentiles for near-term exploitation likelihood. Nessus detection plugins (IDs 306541, 307356, 320414) are available for identifying vulnerable FFmpeg installations (Feedly).
read_global_param() function of libavcodec/av1dec.c.read_global_param() function reads out-of-bounds memory, and the process crashes, causing a Denial of Service for the affected application or service (NVD, GitHub Advisory).ffmpeg, ffprobe, or application processes embedding libavcodec) when processing AV1 video content.libavcodec/av1dec.c or read_global_param()..av1, .ivf, .mkv, .mp4 with AV1 tracks) in upload or processing directories.Upgrade FFmpeg to a version released after 8.0.1 that includes a patch for this vulnerability. As a workaround, restrict AV1 video processing to trusted sources only, and implement input validation or filtering for AV1 streams before they reach the FFmpeg decoder. Disabling AV1 decoding in FFmpeg builds where it is not required can also eliminate the attack surface. Distribution-specific patches have been issued by Mageia (MGASA-2026-0153) and openSUSE, and Chainguard/Wolfi container images have been updated (Feedly).
The vulnerability received routine coverage from vulnerability tracking services including VulDB, CVEFeed, and cve.report shortly after disclosure. The Yocto Project security mailing list discussed the CVE in the context of embedded Linux builds across multiple threads. openSUSE issued security announcements addressing FFmpeg updates that include this fix. No notable researcher commentary or significant social media discussion beyond standard vulnerability aggregation has been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."