CVE-2026-8461
An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.
- Affected products
- Ffmpeg
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.6% (73th percentile)
- Weakness
- CWE-787
- NVD status
- Awaiting Analysis
- Published
- 2026-06-18
- Attack patterns
- CAPEC-100, CAPEC-123, CAPEC-586
- Entry point
- sheight path
- Path
- libavcodec/magicyuv.c
CVE-2026-8461 at NVD
3 known exploits for CVE-2026-8461
Proof-of-concept code and exploit modules indexed by Sploitus