Executive brief
OSSRS SRS is an open-source real-time streaming server that handles live video and audio broadcasts. This vulnerability allows an unauthenticated attacker to publish arbitrary media streams to the server when vhost-level security is disabled, potentially enabling stream hijacking, malicious content injection, or service disruption for legitimate broadcasters.
Technical details
The vulnerability is an authentication bypass in the RTMP publish authorization mechanism, specifically in the SrsSecurity::check() function located in trunk/src/app/srs_app_security.cpp. When vhost-level security (security.enabled) is disabled and no other publish authentication is configured, the RTMP listener component fails to enforce authorization checks, allowing remote attackers to publish streams without credentials. The attack vector is network-based and requires only network reachability to the RTMP listening port; no user interaction or prior authentication is necessary. An attacker can exploit this to inject malicious or unauthorized streams into the server. Patches are available in SRS versions 5.0.213 and later.
Affected products
- OSSRS SRS <5.0.213
Timeline
- 2026-08-17: disclosed