{"apiVersion":"1.0","identifier":"CVE-2026-75146","description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","publishedAt":"2026-08-19T17:21:13","lastModifiedAt":"2026-08-20T15:18:38","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75146","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","epssProbability":0.00261,"riskScore":0.83,"affectedProduct":"FFmpeg","affectedVersions":"unknown","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-75146","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-75146","en":"https://www.redsauce.net/en/cves/CVE-2026-75146","fr":"https://www.redsauce.net/fr/cves/CVE-2026-75146","pt":"https://www.redsauce.net/pt/cves/CVE-2026-75146","de":"https://www.redsauce.net/de/cves/CVE-2026-75146","sk":"https://www.redsauce.net/sk/cves/CVE-2026-75146","el":"https://www.redsauce.net/el/cves/CVE-2026-75146"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-75146"}}