Multiple security vulnerabilities affecting streamlink versions Executed against released `streamlink 8 have been identified in streamlink, affecting versions up to 8.5.0. The overall risk and impact of these vulnerabilities are medium, with an attacker able to read local files by exploiting a scheme downgrade or cross-protocol transition when following HTTP redirects.
CVE-2026-92164 (CVSS 6.5 — Severity): The vulnerability is in the HTTPSession component, which follows HTTP redirects into file:// URLs, reading local files without checking for scheme downgrades or cross-protocol transitions. An attacker can control a URL that a victim's Streamlink run reaches, no privileges on the victim host are required, and the file:// scheme never appears in anything the victim or the manifest parser sees.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting streamlink versions Executed against released `streamlink 8 have been identified in streamlink, affecting versions up to 8.5.0. The overall risk and impact of these vulnerabilities are medium, with an attacker able to read local files by exploiting a scheme downgrade or cross-protocol transition when following HTTP redirects.
CVE-2026-92164 (CVSS 6.5 — Severity): The vulnerability is in the HTTPSession component, which follows HTTP redirects into file:// URLs, reading local files without checking for scheme downgrades or cross-protocol transitions. An attacker can control a URL that a victim's Streamlink run reaches, no privileges on the victim host are required, and the file:// scheme never appears in anything the victim or the manifest parser sees.[emaillocker id="1283"]
CVE-2026-44353: The vulnerability is related to direct file:// segment and playlist URIs in HLS playlists and DASH manifests. The attack surface is the same one that advisory describes, but the flaw is one level down in HTTPSession rather than in the streaming implementations.
We recommend you to update Streamlink to version 8.6.0.
The following reports contain further technical details:
[/emaillocker]