SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38346

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the yuv2planeX_8_c() function of FFmpeg can be exploited by attackers through specially crafted video files, leading to a Denial of Service (DoS) condition. Organizations utilizing FFmpeg for video processing should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-38346
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.