OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-107696 (CVSS 7.1)

NVD · officialPublished Oct 8, 2026Risk 23/100

FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP server can answer every request with a 302 redirect to itself or another server, causing endless reconnects that saturate a CPU core.

CVSS
7.1
AV:NetworkAC:LowPR:NoneUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source