CVE-2026-38347: FFmpeg vulnerability
Published Aug 27, 2026
·Updated
A heap overflow in the ffswsalphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
1 affected component
FFmpeg=git-master commit 722a217
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What must an attacker provide to trigger the denial of service?
An attacker needs to supply a crafted input that reaches the ff_sws_alphablendaway function in libswscale/alphablend.c.
2
Which FFmpeg code state is identified as affected?
The issue is identified in FFmpeg git-master commit 722a217. No affected release versions or fixed versions are provided.