FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Network attackers can intercept https, rtmps, or tls connections to IP-literal URLs with any trusted CA-issued certificate to read and tamper with streams.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-297"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107660.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.1.3"
},
{
"introduced": "9.0"
},
{
"fixed": "9.0.2"
}
],
"source": "AFFECTED_FIELD"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107660.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "105442483210926319160465196797642082364",
"length": 4774
},
"id": "CVE-2026-107660-397b5519",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/1041abdc962f4cc4f394aa8de9dc5236c0c3b9e7",
"target": {
"file": "libavformat/tls_gnutls.c",
"function": "tls_open"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"294743355700093164049687108208873085085",
"224965271620837188898662069401134792161",
"265157521262625521451262118292114363008",
"25267032580962748686041211766260548539",
"288771055614593351168329352873927446828",
"53989852260687713572797447970147499102",
"85263668306260175235908565784155404500",
"126708715019858463115413013055776439727",
"250936792900039357966242742548850663615",
"233269261520550088398052581304792306815",
"100169017263657203071873393627980140697",
"259030622961485660928302215624760282163",
"207706088114512659742213377410159498610",
"240026302395214622814105709906272076705",
"307969978196503324667336784936863433154",
"248723093221806719839251281363761281731",
"295275768641886040795633308418339589772",
"246824707463387711938561227461300764945",
"218915441499077723859496405218262171036",
"287680861236209989555898420906212164973",
"89283821891072419980986328050002025119",
"35321890611978964423610561484240052326",
"293356392578078406821798609450059364653",
"176799238777128513161325516005692082610",
"306300210666150773252873265185691743758",
"172210818910291424728612305586102494925",
"91354717951606701022962506954206737364",
"27898421268780237467740626846927593971",
"43363202001267167103800358854796501422"
],
"threshold": 0.9
},
"id": "CVE-2026-107660-bb8a9c63",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/1041abdc962f4cc4f394aa8de9dc5236c0c3b9e7",
"target": {
"file": "libavformat/tls_gnutls.c"
}
}
]
"2026-10-09T07:06:53Z"