CVE-2026-90783

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

  • Published Sep 13, 2026
  • CVSS 8.5 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-90783 at the National Vulnerability Database