CVE-2026-63269: LFI and GET SSRF via GStreamer and HLS playlists

Published Oct 5, 2026
·
Updated

LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions LibreOffice does not follow playlists that name further resources, and linked media is under link update control.

Affected Software

1 affected component
The Document Foundation LibreOffice

Event History

Oct 5, 2026
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this behavior?

The described behavior applies to LibreOffice on Linux when it plays linked audio or video using GStreamer. A document must contain linked media for the issue to be relevant.

2

What does an attacker need to provide to trigger the issue?

An attacker would need a document whose linked media file is an HLS playlist. The playlist can name local files and remote URLs that GStreamer reads while the document loads.

3

What is the impact of a malicious playlist?

GStreamer may read the local files and remote URLs listed by the playlist, and their contents can end up in the document. This can expose local information and cause requests to remote resources.

4

What changes in fixed versions?

Fixed LibreOffice versions do not follow playlists that name additional resources. Linked media is also subject to link update control.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203