Tools AI-Found Vulnerability Register aifv-0061
Register entry
depthfirst reports 21 FFmpeg zero-days from a $1,000 scan of 1.5 million lines
- Project
- FFmpeg
- Finder
- depthfirst autonomous security agent
- Autonomy
- autonomous agent; each finding with a reproducible proof-of-concept input per the write-up
- Evidence tier
- Aggregate claim
- Bounty
- FFmpeg pays no bounty
- Confidence
- CONFIRMED
What happened
Opened on 19 September 2026: the page dates itself 2 June 2026, names nine CVE identifiers and twelve DFVULN identifiers, and says the twelve are fixed with no CVE assigned yet. The most severe, DFVULN-127, is described as a heap buffer overflow in the AV1 RTP depacketizer reachable from one 183-byte packet.
Credit as recorded: "21 zero-day vulnerabilities in FFmpeg" at a "total cost of roughly $1k" over "roughly 1.5 million lines of heavily optimized C code". Date basis: depthfirst write-up, published 2 June 2026.
Sources
- depthfirst, 21 zero-days in FFmpegdepthfirst.com/research/21-zero-days-in-ffmpeg
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026