We found a division by zero bug in FFmpeg with a vibecoded fuzzer

Hacker News Top News

Summary

A division by zero vulnerability was identified in the FFmpeg multimedia tool through the use of a custom fuzzer, as reported in a software issue.

No content available
Original Article
View Cached Full Text

Cached at: 08/27/26, 06:23 PM

# Making sure you're not a bot! Source: [https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/24290](https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/24290) Loading\.\.\. You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites\. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone\. Anubis is a compromise\. Anubis uses a Proof\-of\-Work scheme in the vein of Hashcash, a proposed proof\-of\-work scheme for reducing email spam\. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive\. Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers \(EG: via how they do font rendering\) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate\. Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable\. Please disable JShelter or other such plugins for this domain\.

Similar Articles

Twenty One Zero-Days in FFmpeg

Hacker News Top

depthfirst's autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg, including several that had remained latent for 15-20 years, with a proof-of-concept demonstrating remote code execution. The findings highlight the capability of AI-driven security agents to uncover critical bugs that evaded previous intensive analyses by Google and Anthropic.

Anonymous GitHub account mass-dropping undisclosed 0-days

Hacker News Top

An anonymous GitHub account has released a large collection of proof-of-concept exploits for undisclosed 0-day vulnerabilities in numerous popular software packages, including 7zip, Docker, Firefox, FFmpeg, Ghidra, libssh2, Nmap, PHP, and VLC.