PatchSiren

streamlink CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM streamlink CVE published 2026-09-23

CVE-2026-92164

CVE-2026-92164 debrief: Streamlink vulnerability allows local file exposure through HTTPSession redirects. A remote server can return a redirect to a local file URL, causing HTTPSession to read the local file and return its contents. This bypasses direct file URL checks added for HLS and DASH content. The flaw applies to every request made through HTTPSession, and a segment fetch can place the local file [truncated]

MEDIUM streamlink CVE published 2026-05-27

CVE-2026-44353

Streamlink versions prior to 8.4.0 contain a path traversal vulnerability in their HLS and DASH parsers. The parsers fail to validate URI schemes in segment entries and other resources within .m3u8 HLS playlists or .mpd DASH manifests. A remote attacker can craft a malicious playlist or manifest that references local files using the file:// scheme (e.g., file:///path/to/file), causing Streamlink to read a [truncated]