CVE-2026-64834Ffmpeg · Ffmpeg
Vulnerability data via NVD (ingested)
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-64834product:"Ffmpeg Ffmpeg"http.html:"Ffmpeg"More intel sources (5)
vuln:CVE-2026-64834vulnerabilities.cve_id: CVE-2026-64834CVE-2026-64834CVE-2026-64834"CVE-2026-64834" exploit -site:nvd.nist.gov