Debian Package Tracker
Register | Log in
Subscribe

streamlink

CLI for extracting video streams from various websites to a video player

Choose email to subscribe with

general
  • source: streamlink (main)
  • version: 8.6.1-1
  • maintainer: Alexis Murzeau (DMD) (DM)
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.0.0-1
  • oldstable: 5.2.1-1
  • old-bpo: 7.3.0-2~bpo12+1
  • stable: 7.3.0-2
  • stable-bpo: 8.4.0-2~bpo13+1
  • testing: 8.6.1-1
  • unstable: 8.6.1-1
versioned links
  • 2.0.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.2.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.3.0-2~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.3.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.4.0-2~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 8.6.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-streamlink
  • python3-streamlink-doc
  • streamlink (1 bugs: 0, 1, 0, 0)
action needed
Marked for autoremoval on 29 October due to sphinxcontrib-log-cabinet: #1147863 high
Version 8.6.1-1 of streamlink is marked for autoremoval from testing on Thu 29 Oct 2026. It depends (transitively) on sphinxcontrib-log-cabinet, affected by #1147863. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-22 Last update: 2026-09-26 06:31
2 security issues in trixie high

There are 2 open security issues in trixie.

1 important issue:
  • CVE-2026-92164: Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting cross-protocol redirects. A remote server controlling an HTTP or HTTPS URL reached by Streamlink can return a redirect to a local file URL, causing HTTPSession to read the local file and return its contents to the response consumer. This bypasses the direct file URL checks added for HLS and DASH content because the manifest contains an ordinary network URL and the scheme transition occurs later during fetch handling. The flaw applies to every request made through HTTPSession, and a segment fetch can place the local file contents into stream output. This issue is fixed in version 8.6.0.
1 issue left for the package maintainer to handle:
  • CVE-2026-44353: (needs triaging) Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. This vulnerability is fixed in 8.4.0.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-05-07 Last update: 2026-09-25 15:00
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-92164: Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting cross-protocol redirects. A remote server controlling an HTTP or HTTPS URL reached by Streamlink can return a redirect to a local file URL, causing HTTPSession to read the local file and return its contents to the response consumer. This bypasses the direct file URL checks added for HLS and DASH content because the manifest contains an ordinary network URL and the scheme transition occurs later during fetch handling. The flaw applies to every request made through HTTPSession, and a segment fetch can place the local file contents into stream output. This issue is fixed in version 8.6.0.
1 issue postponed or untriaged:
  • CVE-2026-44353: (needs triaging) Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. This vulnerability is fixed in 8.4.0.
Created: 2026-09-25 Last update: 2026-09-25 15:00
news
[rss feed]
  • [2026-09-25] streamlink 8.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-21] Accepted streamlink 8.6.1-1 (source) into unstable (Alexis Murzeau)
  • [2026-09-21] Accepted streamlink 8.6.0-1 (source) into unstable (Alexis Murzeau)
  • [2026-08-11] streamlink 8.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-05] Accepted streamlink 8.5.0-1 (source) into unstable (Alexis Murzeau)
  • [2026-06-01] Accepted streamlink 8.4.0-2~bpo13+1 (source) into stable-backports (Alexis Murzeau)
  • [2026-05-23] streamlink 8.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-05-14] Accepted streamlink 8.4.0-2 (source) into unstable (Alexis Murzeau)
  • [2026-05-06] Accepted streamlink 8.4.0-1 (source) into unstable (Alexis Murzeau)
  • [2026-04-18] Accepted streamlink 8.3.0-1~bpo13+1 (source) into stable-backports (Alexis Murzeau)
  • [2026-04-14] streamlink 8.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-10] Accepted streamlink 8.3.0-1 (source) into unstable (Alexis Murzeau)
  • [2026-04-06] streamlink 8.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-03] Accepted streamlink 8.2.1-1 (source) into unstable (Alexis Murzeau)
  • [2026-02-19] Accepted streamlink 8.2.0-1~bpo13+1 (source) into stable-backports (Alexis Murzeau)
  • [2026-02-19] streamlink 8.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-16] Accepted streamlink 8.2.0-1 (source) into unstable (Alexis Murzeau)
  • [2026-01-29] streamlink 8.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-26] Accepted streamlink 8.1.2-1 (source) into unstable (Alexis Murzeau)
  • [2025-12-19] Accepted streamlink 8.1.0-1~bpo13+1 (source) into stable-backports (Alexis Murzeau)
  • [2025-12-18] streamlink 8.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-15] Accepted streamlink 8.1.0-1 (source) into unstable (Alexis Murzeau)
  • [2025-12-04] Accepted streamlink 8.0.0-1~bpo13+1 (source) into stable-backports (Alexis Murzeau)
  • [2025-11-27] streamlink 8.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-24] Accepted streamlink 8.0.0-1 (source) into unstable (Alexis Murzeau)
  • [2025-10-26] streamlink 7.6.0-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-23] Accepted streamlink 7.6.0-2 (source) into unstable (Alexis Murzeau)
  • [2025-10-02] Accepted streamlink 7.6.0-1~bpo13+1 (source all) into stable-backports (Debian FTP Masters) (signed by: Jeroen Ploemen)
  • [2025-09-20] streamlink 7.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-17] Accepted streamlink 7.6.0-1 (source) into unstable (Alexis Murzeau)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 8.6.1-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing