DEBIAN-CVE-2026-44353

Source
https://security-tracker.debian.org/tracker/CVE-2026-44353
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44353.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-44353
Upstream
Published
2026-05-27T17:16:38Z
Modified
2026-09-14T17:03:35Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. This vulnerability is fixed in 8.4.0.

References

Affected packages

Debian:12 / streamlink

Package

Name
streamlink
Purl
pkg:deb/debian/streamlink?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.2.1-1
5.5.1-1~exp1
6.*
6.0.1-1
6.1.0-1
6.2.0-1~bpo12+1
6.2.0-1
6.2.1-1~bpo12+1
6.2.1-1
6.3.0-1
6.3.1-1~bpo12+1
6.3.1-1
6.3.1-2
6.4.2-1~bpo12+1
6.4.2-1
6.5.0-1~bpo12+1
6.5.0-1
6.5.1-1~bpo12+1
6.5.1-1
6.6.1-1
6.6.2-1~bpo12+1
6.6.2-1
6.7.1-1
6.7.2-1~bpo12+1
6.7.2-1
6.7.3-1~bpo12+1
6.7.3-1
6.7.4-1~bpo12+1
6.7.4-1
6.8.1-1
6.8.2-1
6.8.3-1~bpo12+1
6.8.3-1
6.9.0-1~bpo12+1
6.9.0-1
6.10.0-1~bpo12+1
6.10.0-1
6.11.0-1
6.11.0-2~bpo12+1
6.11.0-2
7.*
7.0.0-1~bpo12+1
7.0.0-1
7.1.1-1~bpo12+1
7.1.1-1
7.1.2-1~bpo12+1
7.1.2-1
7.1.3-1~bpo12+1
7.1.3-1
7.2.0-1
7.3.0-1
7.3.0-2~bpo12+1
7.3.0-2
7.5.0-1
7.6.0-1~bpo13+1
7.6.0-1
7.6.0-2
8.*
8.0.0-1~bpo13+1
8.0.0-1
8.1.0-1~bpo13+1
8.1.0-1
8.1.2-1
8.2.0-1~bpo13+1
8.2.0-1
8.2.1-1
8.3.0-1~bpo13+1
8.3.0-1
8.4.0-1
8.4.0-2~bpo13+1
8.4.0-2
8.5.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44353.json"

Debian:13 / streamlink

Package

Name
streamlink
Purl
pkg:deb/debian/streamlink?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.3.0-2
7.5.0-1
7.6.0-1~bpo13+1
7.6.0-1
7.6.0-2
8.*
8.0.0-1~bpo13+1
8.0.0-1
8.1.0-1~bpo13+1
8.1.0-1
8.1.2-1
8.2.0-1~bpo13+1
8.2.0-1
8.2.1-1
8.3.0-1~bpo13+1
8.3.0-1
8.4.0-1
8.4.0-2~bpo13+1
8.4.0-2
8.5.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44353.json"

Debian:14 / streamlink

Package

Name
streamlink
Purl
pkg:deb/debian/streamlink?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.4.0-1

Affected versions

7.*
7.3.0-2
7.5.0-1
7.6.0-1~bpo13+1
7.6.0-1
7.6.0-2
8.*
8.0.0-1~bpo13+1
8.0.0-1
8.1.0-1~bpo13+1
8.1.0-1
8.1.2-1
8.2.0-1~bpo13+1
8.2.0-1
8.2.1-1
8.3.0-1~bpo13+1
8.3.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44353.json"