Technology · Gstreamer
GStreamer vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in GStreamer: 0 in the last 7 days and 5 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18299, was published on 20 August 2026.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 3
- Exploited in the wild
- 0
About GStreamer
A pipeline-based multimedia framework that links together a wide variety of media processing systems to complete complex workflows.
Latest GStreamer vulnerabilities
- CVE-2026-18299: GStreamer rtpsbcdepay use-after-free in RTP SBC payload parsinghighCVSS 7.8EPSS 0.2%
- CVE-2026-18298: GStreamer gst-plugins-good heap buffer overflow in GdkPixbuf decoderhighCVSS 7.8EPSS 0.2%
- CVE-2026-18297: GStreamer Opus decoder stack-based buffer overflowhighCVSS 7.8EPSS 0.2%
- CVE-2026-18296: GStreamer MRF file parsing heap buffer overflowhighCVSS 7.8EPSS 0.2%
- CVE-2026-18295: GStreamer MRF File Parsing Out-Of-Bounds WritehighCVSS 7.8EPSS 0.2%
- CVE-2026-12892: GStreamer gst-plugins-bad heap out-of-bounds read in H.264 parsermediumCVSS 4.4
- CVE-2026-52721: GStreamer out-of-bounds read in pcapparse elementmediumCVSS 5.3
- CVE-2026-3086: GStreamer H.266 Codec Parser out-of-bounds write in APS unitshighCVSS 7.8EPSS 0.4%
- CVE-2026-3085: GStreamer heap overflow in rtpqdm2depay elementhighCVSS 8.8EPSS 0.5%
- CVE-2026-3084: GStreamer H.266 Codec Parser integer underflow in picture partitionshighCVSS 7.8EPSS 0.4%
- CVE-2026-3083: GStreamer rtpqdm2depay out-of-bounds write in X-QDM RTP parsinghighCVSS 8.8EPSS 0.8%
- CVE-2026-3082: GStreamer JPEG Parser heap overflow in Huffman table processinghighCVSS 7.8EPSS 0.6%
- CVE-2026-3081: GStreamer H.266 codec parser stack-based buffer overflowhighCVSS 7.8EPSS 0.4%
- CVE-2026-2923: GStreamer out-of-bounds write in DVB Subtitles handlinghighCVSS 7.8EPSS 0.7%
- CVE-2026-2922: GStreamer RealMedia Demuxer out-of-bounds writehighCVSS 7.8EPSS 0.4%
- CVE-2026-2921: GStreamer RIFF palette integer overflow in AVI handlinghighCVSS 7.8EPSS 0.8%
- CVE-2026-2920: GStreamer heap overflow in ASF demuxerhighCVSS 7.8EPSS 0.7%
- CVE-2025-47219: GStreamer isomp4 plugin out-of-bounds read in qtdemux_parse_trakhighCVSS 8.1
- CVE-2016-9636: GStreamer heap buffer overflow in FLIC decodercriticalCVSS 9.8
- CVE-2016-9635: GStreamer heap buffer overflow in FLIC decodercriticalCVSS 9.8
- CVE-2016-9634: GStreamer heap buffer overflow in FLIC decodercriticalCVSS 9.8
- CVE-2016-9445: GStreamer integer overflow in vmnc decoderhighCVSS 7.5
- CVE-2016-9813: GStreamer NULL pointer dereference in mpegts parsermediumCVSS 5.5
- CVE-2016-9812: GStreamer gst-plugins-bad out-of-bounds read in gst_mpegts_section_newhighCVSS 7.5
- CVE-2016-9810: GStreamer gst-plugins-good denial of service in flxdec decodermediumCVSS 5.5
Most severe GStreamer vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2016-9636: GStreamer heap buffer overflow in FLIC decodercriticalCVSS 9.8
- CVE-2016-9635: GStreamer heap buffer overflow in FLIC decodercriticalCVSS 9.8
- CVE-2016-9634: GStreamer heap buffer overflow in FLIC decodercriticalCVSS 9.8
- CVE-2026-3083: GStreamer rtpqdm2depay out-of-bounds write in X-QDM RTP parsinghighCVSS 8.8EPSS 0.8%
- CVE-2026-3085: GStreamer heap overflow in rtpqdm2depay elementhighCVSS 8.8EPSS 0.5%
- CVE-2025-47219: GStreamer isomp4 plugin out-of-bounds read in qtdemux_parse_trakhighCVSS 8.1
- CVE-2026-2921: GStreamer RIFF palette integer overflow in AVI handlinghighCVSS 7.8EPSS 0.8%
- CVE-2026-2920: GStreamer heap overflow in ASF demuxerhighCVSS 7.8EPSS 0.7%
- CVE-2026-2923: GStreamer out-of-bounds write in DVB Subtitles handlinghighCVSS 7.8EPSS 0.7%
- CVE-2026-3082: GStreamer JPEG Parser heap overflow in Huffman table processinghighCVSS 7.8EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/gstreamer.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "GStreamer vulnerabilities", https://junglewise.ai/threats/technologies/gstreamer, 26 September 2026.