{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/gst-plugins-good/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18649"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gst-plugins-good"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","memory-exhaustion","gstreamer"],"_cs_type":"advisory","_cs_vendors":["GStreamer"],"content_html":"\u003cp\u003eCVE-2026-18649 describes a critical denial of service vulnerability in the GStreamer gst-plugins-good package. The flaw resides within the rtph264depay and rtph265depay elements, which are responsible for depayloading H.264 and H.265 video streams respectively. These elements fail to implement a maximum size limit on the reassembly buffer when processing fragmented RTP packets. By intentionally sending a continuous stream of RTP fragments that lacks a proper end-of-fragment marker, an unauthenticated remote attacker can force the application to allocate memory continuously. This behavior leads to heap memory exhaustion and the eventual termination of the GStreamer-based process. This vulnerability affects any application or multimedia framework utilizing these specific GStreamer elements for RTP stream handling, potentially causing service outages in streaming infrastructure or media processing pipelines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate denial of service for the target application or service relying on GStreamer for media ingestion. Because the process terminates due to memory exhaustion, any active streams being handled by the process are dropped. Given the widespread use of GStreamer in media servers, embedded devices, and surveillance systems, the impact can range from local service disruption to wide-scale outages of media processing infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the GStreamer gst-plugins-good package to the latest patched version across all affected environments as identified by the vendor's security advisory.\u003c/li\u003e\n\u003cli\u003eAudit network ingress traffic for incoming RTP streams targeting GStreamer-based services to identify unusual traffic volumes or long-duration fragmented RTP sessions.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for process-level memory consumption on servers hosting GStreamer pipelines to detect anomalies characteristic of memory exhaustion attacks.\u003c/li\u003e\n\u003cli\u003eConsult the GStreamer security bulletin for specific version numbers that include the patch for CVE-2026-18649.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T11:23:04Z","date_published":"2026-08-06T11:23:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gstreamer-dos/","summary":"A heap memory exhaustion vulnerability in the GStreamer gst-plugins-good package allows unauthenticated attackers to crash services via unbounded reassembly buffer growth.","title":"Denial of Service Vulnerability in GStreamer gst-plugins-good","url":"https://feed.craftedsignal.io/briefs/2026-08-gstreamer-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Gst-Plugins-Good","version":"https://jsonfeed.org/version/1.1"}