PatchSiren cyber security CVE debrief
CVE-2026-107698 FFmpeg CVE debrief
FFmpeg before 7.1.4 and 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Location URL. Malicious RTSP servers can redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services.
- Vendor
- FFmpeg
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and administrators of FFmpeg installations should assess exposure and apply patches. They should also review configurations, monitor for suspicious activity, and implement compensating controls where necessary. Vulnerability management and security teams should prioritize verifying FFmpeg versions and applying patches to prevent potential SSRF attacks.
Why it matters
Defenders should care about this vulnerability as it allows malicious RTSP servers to probe internal network services, potentially leading to SSRF attacks.
- Potential SSRF attacks on internal network services
- Bypassing of -protocol_whitelist configurations
- Probing of internal hosts and ports
Technical summary
FFmpeg before 7.1.4 and 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c, allowing malicious RTSP servers to redirect FFmpeg to internal hosts and ports under other schemes, bypassing -protocol_whitelist, to probe internal network services. This vulnerability affects FFmpeg installations and defenders should assess exposure and apply patches accordingly. The vulnerability is triggered by RTSP 3xx redirects without validating the Location URL, which can lead to SSRF attacks.
Defensive priority
Defenders should prioritize verifying FFmpeg versions and applying patches to prevent potential SSRF attacks.
Recommended defensive actions
- Verify FFmpeg versions and apply patches
- Review and update -protocol_whitelist configurations
- Monitor for suspicious RTSP activity
- Perform vulnerability scanning
- Implement compensating controls
- Review asset inventory
- Track changes to FFmpeg configurations
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and patch commits. Defenders should verify FFmpeg versions, review configurations, and monitor for suspicious activity. Evidence limits are based on CVE and source item details. Affected scope and severity are confirmed via CVE metadata. No additional facts are claimed beyond source grounding.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107698 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107698
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107698 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107698
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107698.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/commit/ea9e85e54981b8402368d0f21648836d6738f1b1
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/commit/2326bc5f69c9
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/commit/7c011995e394
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/commit/f9aa8729bce1
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22292
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/blob/n7.1.3/libavformat/rtsp.c
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg
Supplemental source - product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.