CVE-2026-30999: Buffer Overflow
Published Apr 13, 2026
·Updated
A heap buffer overflow in the avbprintfinalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
2 affected components
FFmpeg FFmpeg=8.0.1
FFmpeg FFmpeg<=8.0.1
Event History
Apr 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30999?
CVE-2026-30999 is classified as a critical vulnerability due to its potential to cause a Denial of Service.
2
How do I fix CVE-2026-30999?
To fix CVE-2026-30999, you should upgrade to a version of FFmpeg that is higher than 8.0.1.
3
What components are affected by CVE-2026-30999?
CVE-2026-30999 specifically affects FFmpeg version 8.0.1.
4
What is the impact of CVE-2026-30999?
The impact of CVE-2026-30999 is that it allows attackers to exploit a heap buffer overflow, leading to a Denial of Service.
5
Who is vulnerable to CVE-2026-30999?
Any user or organization using FFmpeg version 8.0.1 is vulnerable to CVE-2026-30999.