CVE-2026-64830Ffmpeg · Ffmpeg
Vulnerability data via NVD (ingested)
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-64830product:"Ffmpeg Ffmpeg"http.html:"Ffmpeg"More intel sources (5)
vuln:CVE-2026-64830vulnerabilities.cve_id: CVE-2026-64830CVE-2026-64830CVE-2026-64830"CVE-2026-64830" exploit -site:nvd.nist.gov