PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107698 FFmpeg CVE debrief

FFmpeg before 7.1.4 and 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services.

Vendor
FFmpeg
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders and administrators of FFmpeg installations should assess exposure and apply patches. They should also review configurations, monitor for suspicious activity, and implement compensating controls where necessary. Vulnerability management and security teams should prioritize verifying FFmpeg versions and applying patches to prevent potential SSRF attacks.

Why it matters

Defenders should care about this vulnerability as it allows malicious RTSP servers to probe internal network services, potentially leading to SSRF attacks.

  • Potential SSRF attacks on internal network services
  • Bypassing of -protocol_whitelist configurations
  • Probing of internal hosts and ports

Technical summary

FFmpeg before 7.1.4 and 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c, allowing malicious RTSP servers to redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services. This vulnerability affects FFmpeg installations and defenders should assess exposure and apply patches accordingly. The vulnerability is triggered by RTSP 3xx redirects without validating the Location URL, which can lead to SSRF attacks.

Defensive priority

Defenders should prioritize verifying FFmpeg versions and applying patches to prevent potential SSRF attacks.

Recommended defensive actions

  • Verify FFmpeg versions and apply patches
  • Review and update -protocol_whitelist configurations
  • Monitor for suspicious RTSP activity
  • Perform vulnerability scanning
  • Implement compensating controls
  • Review asset inventory
  • Track changes to FFmpeg configurations

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and patch commits. Defenders should verify FFmpeg versions, review configurations, and monitor for suspicious activity. Evidence limits are based on CVE and source item details. Affected scope and severity are confirmed via CVE metadata. No additional facts are claimed beyond source grounding.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107698 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107698

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107698 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107698

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107698.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg/commit/ea9e85e54981b8402368d0f21648836d6738f1b1

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg/commit/2326bc5f69c9

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg/commit/7c011995e394

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg/commit/f9aa8729bce1

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22292

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg/blob/n7.1.3/libavformat/rtsp.c

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FFmpeg/FFmpeg

    Supplemental source - product

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.