SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38347

HIGH · CVSS 7.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A heap overflow vulnerability in the ff_sws_alphablendaway function of FFmpeg can be exploited by attackers to trigger a Denial of Service (DoS) through specially crafted input. This issue affects unspecified versions of FFmpeg, and organizations using this multimedia framework should prioritize patching or mitigating this vulnerability to prevent potential service disruptions.

CVE
CVE-2026-38347
Severity
HIGH
CVSS
7.5
EPSS
0.33%

Original NVD Description

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.