YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0050

Register entry

FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve

CVE
CVE-2026-39212
Project
FFmpeg
Component
FFmpeg component per the write-up
Finder
depthfirst autonomous security agent
Autonomy
autonomous agent; reproducible proof-of-concept input per the write-up
Evidence tier
Identifier claimed, record unserved
Bounty
FFmpeg pays no bounty
Confidence
UNVERIFIED

What happened

One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine "have already been assigned CVEs"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.

Credit as recorded: no record: the identifier answers HTTP 404 at the cvelistV5 mirror. Record status: HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026. Date basis: depthfirst write-up, published 2 June 2026.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026