Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core. | |
| Title | FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c | |
| First Time appeared |
Ffmpeg
Ffmpeg ffmpeg |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ffmpeg
Ffmpeg ffmpeg |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T17:30:27.515Z
Reserved: 2026-10-08T16:51:39.862Z
Link: CVE-2026-107696
No data.
Status : Received
Published: 2026-10-08T18:17:26.133
Modified: 2026-10-08T18:17:26.133
Link: CVE-2026-107696
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:15:20Z
-
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')