PixelSmash: Critical FFmpeg flaw lets attackers execute code via malicious video files
CVE-2026-8461, a heap overflow in FFmpeg's MagicYUV decoder rated CVSS 8.8, affects Jellyfin, Nextcloud, OBS Studio, Kodi, and potentially Slack, Discord, and Telegram. Patch now: FFmpeg 8.1.2.










