YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0061

Register entry

depthfirst reports 21 FFmpeg zero-days from a $1,000 scan of 1.5 million lines

Project
FFmpeg
Finder
depthfirst autonomous security agent
Autonomy
autonomous agent; each finding with a reproducible proof-of-concept input per the write-up
Evidence tier
Aggregate claim
Bounty
FFmpeg pays no bounty
Confidence
CONFIRMED

What happened

Opened on 19 September 2026: the page dates itself 2 June 2026, names nine CVE identifiers and twelve DFVULN identifiers, and says the twelve are fixed with no CVE assigned yet. The most severe, DFVULN-127, is described as a heap buffer overflow in the AV1 RTP depacketizer reachable from one 183-byte packet.

Credit as recorded: "21 zero-day vulnerabilities in FFmpeg" at a "total cost of roughly $1k" over "roughly 1.5 million lines of heavily optimized C code". Date basis: depthfirst write-up, published 2 June 2026.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026