JLSEC-2026-1183

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1183.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1183.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1183
Upstream
  • EUVD-2026-48739
  • GHSA-qqrg-chvw-q8jp
Published
2026-08-07T13:27:45.313Z
Modified
2026-08-08T23:15:05.743264260Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption...
Details

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66037",
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2026-08-07T00:58:46.967Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-66037",
            "imported": "2026-08-08T05:24:16.208Z",
            "id": "CVE-2026-66037",
            "published": "2026-07-24T20:18:20.573Z"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-qqrg-chvw-q8jp",
            "imported": "2026-08-08T05:24:56.116Z",
            "modified": "2026-07-24T21:32:28Z",
            "url": "https://api.github.com/advisories/GHSA-qqrg-chvw-q8jp",
            "id": "GHSA-qqrg-chvw-q8jp",
            "published": "2026-07-24T21:32:22Z"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48739",
            "imported": "2026-08-08T05:24:18.416Z",
            "modified": "2026-07-28T01:06:28Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-48739",
            "id": "EUVD-2026-48739",
            "published": "2026-07-24T19:36:53Z"
        }
    ]
}
References

Affected packages

Julia / FFMPEG_jll

Package

Name
FFMPEG_jll
Purl
pkg:julia/FFMPEG_jll?uuid=b22a6f82-2f65-5046-a5b2-351ab43fb4e5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1183.json"

Julia / FFMPEG_nogpl_jll

Package

Name
FFMPEG_nogpl_jll
Purl
pkg:julia/FFMPEG_nogpl_jll?uuid=a6892c6b-5768-548c-b024-ff8dabf482c5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1183.json"

Julia / FFplay_jll

Package

Name
FFplay_jll
Purl
pkg:julia/FFplay_jll?uuid=c4dce911-e170-5107-8314-c7bdc6785395

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1183.json"