CVE-2026-8461
CVSS 8.8 HIGH: an out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows… EPSS 2% (73rd percentile).
Vulnerabilities · 83 days ago
A crash in FFmpeg’s MagicYUV decoder is a cross-application code execution path. If a product embeds libavcodec, patching only the visible media app or server can leave the vulnerable decoder in place inside file managers, NAS appliances, preview generators, and transcoding services.
JFrog says CVE-2026-8461 is a heap out-of-bounds write in FFmpeg 8.1.2’s fixed release, and that crafted media can push the bug from denial of service to remote code execution. The issue affects FFmpeg-based software such as OBS Studio and Jellyfin, and the exploit payload can be as small as a 50 KB media file.
The remaining risk is embedded reuse. Any application that auto-opens untrusted media for thumbnails, previews, or transcoding inherits the same RCE path until its bundled FFmpeg is updated.
CVSS 8.8 HIGH: an out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows… EPSS 2% (73rd percentile).
3 sources covering this story
Hole in widely-used FFmpeg codec could crash media servers or enable RCE
Research from JFrog into the software supply chain vulnerability points to the need for better visibility into applications, including SBOMs.
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library.
FFmpeg fixes PixelSmash flaw in widely used video decoder
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.
Part of the PlainSec briefing for 2026-06-24