SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38349

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the hScale16To19_c() function of FFmpeg can be exploited by attackers through specially crafted image files, leading to a Denial of Service (DoS) condition. Organizations using affected versions of FFmpeg should prioritize this issue to mitigate potential disruptions in service. Users handling image processing or media streaming should be particularly vigilant in applying patches or workarounds.

CVE
CVE-2026-38349
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.