CVE-2025-27091 is a heap overflow vulnerability in the OpenH264 codec library (versions 2.5.0 and earlier) affecting both Scalable Video Coding (SVC) and Advanced Video Coding (AVC) modes. This critical flaw stems from a race condition during H.264 decoding, allowing a remote, unauthenticated attacker to trigger a crash and potentially execute arbitrary commands by tricking a victim into processing a specially crafted malicious video bitstream. With a CVSS score of 7.5 (HIGH), exploitation requires user interaction (UI:R) but could lead to high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). There is currently no known active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.1CPE matchmatch criteria | cpe:2.3:a:cisco:openh264:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.