CVE-2026-82821
A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52642f7dfb76ec7334016622dde60b1ae963d79b. To fix this issue, it is recommended to deploy a patch. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.33%
- CWE
- CWE-476, CWE-404
- Published
- 2026-08-31
- Last modified
- 2026-08-31
Affected products
- n/a FLVMeta
- n/a FLVMeta
- n/a FLVMeta
Weakness type
Related vulnerabilities
- CVE-2026-78130 — strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute...
- CVE-2026-78126 — strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- CVE-2026-45747 — Suricata lua/tls: null dereference in TlsGetCertInfo
- CVE-2026-86547 — mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
- CVE-2026-66303 — Skype for Business and Lync Denial of Service Vulnerability
- CVE-2026-77901 — Microsoft Office Word Remote Code Execution Vulnerability
- CVE-2026-70575 — Windows Schannel Denial of Service Vulnerability
- CVE-2026-69881 — Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability