FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any… (CVE-2026-107696)
Description
FFmpeg versions through 9.0.2 have an infinite loop vulnerability in the ff_rtsp_connect() function within libavformat/rtsp.c. This flaw occurs because the function follows RTSP 3xx redirect responses without any limit on the number of redirects. An attacker controlling an RTSP server can exploit this by responding to requests with repeated 302 redirects to itself or another server, causing the client to enter an endless reconnect loop that saturates a CPU core.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in FFmpeg up to version 9.0.2 is an infinite loop in the RTSP connection handling code (ff_rtsp_connect in libavformat/rtsp.c). The function does not impose a limit on following RTSP 3xx redirect responses, allowing an attacker controlling an RTSP server to cause the client to continuously reconnect by issuing 302 redirects to itself or other servers. This results in a denial-of-service condition by saturating a CPU core.
Potential Impact
This vulnerability can be exploited by an attacker controlling an RTSP server to cause a denial-of-service (DoS) condition on clients using vulnerable FFmpeg versions. The endless reconnect loop consumes CPU resources, potentially degrading or disrupting service availability. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid connecting to untrusted RTSP servers or implement external controls to limit redirect handling.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jmpw-6qm3-5h67
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-107696"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac80f122cdf04f65639052c
Added to database: 10/08/2026, 21:45:54 UTC
Last enriched: 10/08/2026, 21:50:57 UTC
Last updated: 10/08/2026, 23:28:24 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.