CVE-2026-70631Disclosure(ffmpeg / ffmpeg)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ffmpeg

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ffmpeg

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-08: 1Technical Details · 2026-08-08: 108-08
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🎬 FFmpeg flaw may leak server memory CVE-2026-70631 affects FFmpeg versions before 9.0. A specially crafted TIFF image can cause the decoder to include uninitialized heap memory in generated output, potentially exposing data left behind by previous allocations. 🔎 Source: FFmpeg / Tenable. #FFmpeg #MemorySafety #DataLeak #CVE #CyberSecurity

    Post summary

    CVE-2026-70631 is a memory‑leak vulnerability in FFmpeg versions before 9.0, triggered by specially crafted TIFF images, with no mention of active exploitation, patches, or PoC.

    0000053
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appffmpegffmpeg---

Explore more