CVE-2026-107660
Discovered by AISLEPUBLISHEDCWE-297
Description
FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-issued certificate to read and tamper with streams.
CVSS Base Scores
CVSS v4.06.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| FFmpeg | — | — |

