JLSEC-2026-1186

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1186.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1186.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1186
Upstream
  • EUVD-2026-48742
  • GHSA-6vcg-882j-82v5
Published
2026-08-07T13:27:45.313Z
Modified
2026-08-07T13:43:40.045809608Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
Details

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.

Database specific
{
    "sources": [
        {
            "modified": "2026-08-07T00:35:29.773Z",
            "database_specific": {
                "status": "Analyzed"
            },
            "id": "CVE-2026-66040",
            "published": "2026-07-24T20:18:21.063Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-66040",
            "imported": "2026-08-07T05:41:14.792Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66040"
        },
        {
            "modified": "2026-07-24T21:32:28Z",
            "published": "2026-07-24T21:32:22Z",
            "id": "GHSA-6vcg-882j-82v5",
            "url": "https://api.github.com/advisories/GHSA-6vcg-882j-82v5",
            "imported": "2026-08-07T05:41:17.315Z",
            "html_url": "https://github.com/advisories/GHSA-6vcg-882j-82v5"
        },
        {
            "modified": "2026-07-29T03:55:38Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48742",
            "id": "EUVD-2026-48742",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-48742",
            "imported": "2026-08-07T05:41:15.149Z",
            "published": "2026-07-24T19:46:25Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / FFMPEG_jll

Package

Name
FFMPEG_jll
Purl
pkg:julia/FFMPEG_jll?uuid=b22a6f82-2f65-5046-a5b2-351ab43fb4e5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1186.json"

Julia / FFMPEG_nogpl_jll

Package

Name
FFMPEG_nogpl_jll
Purl
pkg:julia/FFMPEG_nogpl_jll?uuid=a6892c6b-5768-548c-b024-ff8dabf482c5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1186.json"

Julia / FFplay_jll

Package

Name
FFplay_jll
Purl
pkg:julia/FFplay_jll?uuid=c4dce911-e170-5107-8314-c7bdc6785395

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1186.json"