
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-90816 is a denial-of-service vulnerability in FFmpeg 8.0.x affecting the parse_playlist function in libavformat/hlsproto.c within the HLS Duration Parser component. Manipulation of the duration or target_duration arguments can cause improper resource shutdown or release, leading to a denial-of-service condition. The vulnerability was published on September 14, 2026, and is currently awaiting full NVD analysis. It carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Feedly, VulDB).
The root cause is classified as CWE-404 (Improper Resource Shutdown or Release), where the parse_playlist function in libavformat/hlsproto.c fails to properly handle malformed or unexpected values in the duration and target_duration fields of an HLS playlist. An attacker can exploit this remotely by serving a crafted HLS playlist to a vulnerable FFmpeg 8.0.x client, requiring user interaction (e.g., the user opening or processing the malicious stream). The fix is identified as commit 64fafd63f0b4 in the FFmpeg repository (VulDB, FFmpeg Commit, FFmpeg Issue).
Successful exploitation results in a denial-of-service condition limited to availability impact (low severity), with no confidentiality or integrity compromise. An attacker who can cause a user or automated system to process a malicious HLS playlist can crash or hang the affected FFmpeg process, disrupting media processing pipelines or applications relying on FFmpeg for streaming. The scope is unchanged, meaning the impact is confined to the vulnerable component itself without lateral spread (Feedly, VulDB).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-90816. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — a victim must open or process a crafted HLS stream — which further reduces practical exploitability (Feedly, VulDB).
.m3u8 HLS playlist file containing malformed or extreme values in the #EXTINF (duration) or #EXT-X-TARGETDURATION (target_duration) tags designed to trigger improper resource handling in FFmpeg's parse_playlist function.parse_playlist in libavformat/hlsproto.c processes the malformed duration values, triggering improper resource shutdown/release and causing the FFmpeg process to crash or become unresponsive (VulDB, FFmpeg Issue)..m3u8 playlist files from unknown or suspicious external hosts; HLS playlists with anomalous #EXTINF or #EXT-X-TARGETDURATION field values (e.g., negative numbers, extremely large integers, or non-numeric strings).hlsproto.c or parse_playlist; application logs showing unexpected FFmpeg process termination during HLS stream processing.Users should upgrade FFmpeg from the affected 8.0.x branch to version 8.1 or 9.0, which contain the fix introduced in commit 64fafd63f0b4. No configuration-based workaround has been published; upgrading is the recommended remediation. As an interim measure, organizations can restrict FFmpeg-based applications from processing untrusted or externally sourced HLS streams until patching is complete (VulDB, FFmpeg Commit).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
ffmpeg
devel
ffmpeg
focal (esm-apps)
ffmpeg
jammy
ffmpeg
jammy (esm-apps)
ffmpeg
noble
ffmpeg
noble (esm-apps)
ffmpeg
resolute
ffmpeg
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."