AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18649

HIGH · CVSS 7.5 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The GStreamer gst-plugins-good package contains a vulnerability in the rtph264depay and rtph265depay RTP depayloader elements, which fail to enforce a maximum size limit on the reassembly buffer during fragmented RTP packet processing. This allows a remote, unauthenticated attacker to send an unlimited stream of RTP fragments, leading to potential denial of service by exhausting process memory and terminating the affected service. Organizations using GStreamer in their media processing workflows should prioritize remediation to mitigate this risk.

CVE
CVE-2026-18649
Severity
HIGH
CVSS
7.5
EPSS
0.56%

Original NVD Description

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.