What is CVE-2026-66037?
CVE-2026-66037 is an uncontrolled resource consumption vulnerability in the IAMF demuxer of FFmpeg. An unauthenticated attacker can trigger massive memory allocation using a small crafted file with a malicious count_label field. Updating FFmpeg to a version with the fix commit is strongly recommended.
Azərbaycanca: CVE-2026-66037 FFmpeg-in IAMF demuxer komponentində nəzarətsiz resurs istehlakı zəifliyidir. Uzaqdan autentifikasiya olunmamış hücumçu, xüsusi hazırlanmış kiçik fayl vasitəsilə çox böyük həcmdə yaddaş ayrılmasına səbəb ola bilər. FFmpeg-i müvafiq commit tətbiq edilmiş versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: FFmpeg
FAQ1
Does exploiting CVE-2026-66037 require authentication?
No, this vulnerability can be exploited remotely by an unauthenticated attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.