CVE-2026-64831Ffmpeg · Ffmpeg
Vulnerability data via NVD (ingested)
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-64831product:"Ffmpeg Ffmpeg"http.html:"Ffmpeg"More intel sources (5)
vuln:CVE-2026-64831vulnerabilities.cve_id: CVE-2026-64831CVE-2026-64831CVE-2026-64831"CVE-2026-64831" exploit -site:nvd.nist.gov