FFmpeg
FFmpeg
See the latest tracked release, confirm when it was published, and subscribe for update emails.
7.0.3
- Release date
- August 05, 2025
- Security status
- Current version appears affected by 6 high-severity CVEs.
Source
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 7.0.3 | 2025-08-05 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-58049 | HIGH (8.8) | 2026-06-28 | Current versionaffected | FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption. Affected versions
|
| CVE-2026-8461 | HIGH (8.8) | 2026-06-18 | Current versionaffected | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2. Affected versions
|
| CVE-2026-40962 | CRITICAL (9.8) | 2026-04-16 | Current versionaffected | FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c. Affected versions
|
| CVE-2026-30999 | HIGH (7.5) | 2026-04-13 | Current versionaffected | A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Affected versions
|
| CVE-2026-30998 | HIGH (7.5) | 2026-04-13 | Current versionaffected | An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file. Affected versions
|
| CVE-2026-30997 | HIGH (7.5) | 2026-04-13 | Current versionaffected | An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Affected versions
|