FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that… (CVE-2026-107698)
Description
A server-side request forgery (SSRF) vulnerability exists in FFmpeg versions before 7.1.4 and 8.0.x before 8.0.2 in the ff_rtsp_connect() function within libavformat/rtsp.c. This flaw allows malicious RTSP servers to redirect FFmpeg to internal hosts and ports using other schemes, bypassing the -protocol_whitelist option. The vulnerability is identified as CVE-2026-107698 and has a medium severity rating with a CVSS score of 5.4.
CVSS v3.1
Score 5.4medium
Affected software
pkg:github/ffmpeg/FFmpegRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in the ff_rtsp_connect() function in libavformat/rtsp.c. The vulnerability arises because FFmpeg follows RTSP 3xx redirects without validating the Location URL. This allows a malicious RTSP server to redirect FFmpeg to internal network hosts and ports, potentially bypassing the -protocol_whitelist restriction, enabling probing of internal network services.
Potential Impact
An attacker controlling a malicious RTSP server can exploit this vulnerability to cause FFmpeg to send requests to internal network hosts and ports that would otherwise be inaccessible. This can lead to unauthorized internal network reconnaissance. The impact is limited to information disclosure and network probing, with no direct impact on confidentiality, integrity, or availability of FFmpeg itself.
Mitigation Recommendations
No explicit patch or fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should be cautious when processing RTSP streams from untrusted sources and consider restricting network access or using network-level controls to limit FFmpeg's ability to reach internal services.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jhxg-38qw-fjxv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-107698"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac80f122cdf04f65639052d
Added to database: 10/08/2026, 21:45:54 UTC
Last enriched: 10/08/2026, 21:51:02 UTC
Last updated: 10/08/2026, 23:28:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.