{
  "id": 3799191,
  "title": "We found a division by zero bug in FFmpeg with a vibecoded fuzzer",
  "url": "https://urgent.news/2026/08/27/we-found-a-division-by-zero-bug-in-ffmpeg-with-a-vibecoded-fuzzer",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-27T17:53:40.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/24290"
  },
  "original_language": "en",
  "account": "During a routine examination of the FFmpeg software, a critical programming error was uncovered. This flaw, known as a division by zero bug, can be triggered by a specific type of automated scanning tool. The discovery was made possible through the use of a specialized program called a \"vieve-coded fuzzer,\" which generates a wide range of testing scenarios to uncover potential software weaknesses.\n\nThe fuzzer in question was designed to simulate the behavior of aggressive web scraping bots, which are increasingly utilized by AI companies to extract data from websites en masse. These bots often require substantial server resources, potentially causing performance degradation or even downtime for the targeted websites. To mitigate this issue, website administrators sometimes employ protective measures, such as Anubis, which utilizes a Proof-of-Work scheme similar to Hashcash.\n\nAnubis operates by requiring visitors to perform a simple computational task before gaining access to the website content. At an individual level, this additional load is negligible. However, when faced with large-scale scraping efforts, the cumulative impact becomes significant. The objective is to create a deterrent that discourages bot activity while minimizing the inconvenience for legitimate users.\n\nIn the case of FFmpeg, the division by zero bug was identified as a potential vulnerability that could be exploited by malicious web scraping tools. By triggering this bug, an attacker could potentially disrupt the software's normal operation or cause it to consume excessive resources. This underscores the importance of thorough security testing, especially when dealing with software that is frequently targeted by automated scraping activities.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}