Tools AI-Found Vulnerability Register aifv-0055
Register entry
FFmpeg memory safety in the FFmpeg component per the write-up, claimed by depthfirst under an identifier the CVE list does not yet serve
- CVE
- CVE-2026-39217
- Project
- FFmpeg
- Component
- FFmpeg component per the write-up
- Finder
- depthfirst autonomous security agent
- Autonomy
- autonomous agent; reproducible proof-of-concept input per the write-up
- Evidence tier
- Identifier claimed, record unserved
- Bounty
- FFmpeg pays no bounty
- Confidence
- UNVERIFIED
What happened
One of nine identifiers depthfirst quotes for its FFmpeg run, which scanned roughly 1.5 million lines of C for about $1,000 and reported 21 zero-days. The write-up says nine "have already been assigned CVEs"; the CVE Program's own list answered 404 for every one on 12 September and again on 19 September 2026, so the row stands as a claim until a record serves.
Credit as recorded: no record: the identifier answers HTTP 404 at the cvelistV5 mirror. Record status: HTTP 404 at raw.githubusercontent.com/CVEProject/cvelistV5 on 12 and 19 September 2026. Date basis: depthfirst write-up, published 2 June 2026.
Sources
- depthfirst, 21 zero-days in FFmpegdepthfirst.com/research/21-zero-days-in-ffmpeg
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026