6
CVE-2026-107675
- EPSS 0.19%
- Veröffentlicht 08.10.2026 15:28:41
- Zuletzt bearbeitet 08.10.2026 21:04:38
- Erkennungen
FFmpeg through 9.0.2 Missing SSH Host Key Verification in sftp Protocol
FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwords supplied in sftp URLs, serve forged media, or receive uploaded output.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFFmpeg
≫
Produkt
FFmpeg
Default Statusunaffected
Version <=
9.0.2
Version
0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 6 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 5.9 | 1.6 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
|
CWE-322 Key Exchange without Entity Authentication
The product performs a key exchange with an actor without verifying the identity of that actor.
https://ffmpeg.org/
https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24384
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2b822b7fb6ed195546bc9fd9bdb794e98222bdce
https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/libssh.c#L60-L110
https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-missing-ssh-host-key-verification-in-sftp-protocol