{"schema_version":1,"title":"Gstreamer vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 39 vulnerabilities in Gstreamer: 0 in the last 7 days and 9 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85150, was published on 3 September 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/gstreamer","json_url":"https://junglewise.ai/threats/vendors/gstreamer.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/gstreamer","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":28,"all_time":39,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":9,"last_365_days":28},"latest":[{"cve":"CVE-2026-85150","cvss":7.5,"epss":0.0053,"slug":"cve-2026-85150-gstreamer-null-pointer-dereference-in-rtsp-authentication-parsing","title":"GStreamer NULL pointer dereference in RTSP authentication parsing","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:21.91+00:00","url":"https://junglewise.ai/threats/cve-2026-85150-gstreamer-null-pointer-dereference-in-rtsp-authentication-parsing"},{"cve":"CVE-2026-18299","cvss":7.8,"epss":0.0021,"slug":"cve-2026-18299-gstreamer-rtpsbcdepay-use-after-free-in-rtp-sbc-payload-parsing","title":"GStreamer rtpsbcdepay use-after-free in RTP SBC payload parsing","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:26.767+00:00","url":"https://junglewise.ai/threats/cve-2026-18299-gstreamer-rtpsbcdepay-use-after-free-in-rtp-sbc-payload-parsing"},{"cve":"CVE-2026-18298","cvss":7.8,"epss":0.0024,"slug":"cve-2026-18298-gstreamer-gst-plugins-good-heap-buffer-overflow-in-gdkpixbuf","title":"GStreamer gst-plugins-good heap buffer overflow in GdkPixbuf decoder","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:26.643+00:00","url":"https://junglewise.ai/threats/cve-2026-18298-gstreamer-gst-plugins-good-heap-buffer-overflow-in-gdkpixbuf"},{"cve":"CVE-2026-18297","cvss":7.8,"epss":0.0024,"slug":"cve-2026-18297-gstreamer-opus-decoder-stack-based-buffer-overflow","title":"GStreamer Opus decoder stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:26.507+00:00","url":"https://junglewise.ai/threats/cve-2026-18297-gstreamer-opus-decoder-stack-based-buffer-overflow"},{"cve":"CVE-2026-18296","cvss":7.8,"epss":0.0023,"slug":"cve-2026-18296-gstreamer-mrf-file-parsing-heap-buffer-overflow","title":"GStreamer MRF file parsing heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:26.39+00:00","url":"https://junglewise.ai/threats/cve-2026-18296-gstreamer-mrf-file-parsing-heap-buffer-overflow"},{"cve":"CVE-2026-18295","cvss":7.8,"epss":0.0021,"slug":"cve-2026-18295-gstreamer-mrf-file-parsing-out-of-bounds-write","title":"GStreamer MRF File Parsing Out-Of-Bounds Write","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:26.26+00:00","url":"https://junglewise.ai/threats/cve-2026-18295-gstreamer-mrf-file-parsing-out-of-bounds-write"},{"cve":"CVE-2026-59692","cvss":7.5,"slug":"cve-2026-59692-gstreamer-dtls-plugin-stack-buffer-overflow-in-openssl-verify","title":"GStreamer DTLS plugin stack buffer overflow in openssl_verify_callback","severity":"high","exploited":false,"published_at":"2026-07-09T11:16:41.783+00:00","url":"https://junglewise.ai/threats/cve-2026-59692-gstreamer-dtls-plugin-stack-buffer-overflow-in-openssl-verify"},{"cve":"CVE-2026-59691","cvss":7.1,"slug":"cve-2026-59691-gstreamer-rfbsrc-heap-buffer-overflow-in-hextile-decoding","title":"GStreamer rfbsrc heap buffer overflow in Hextile decoding","severity":"high","exploited":false,"published_at":"2026-07-09T11:16:41.657+00:00","url":"https://junglewise.ai/threats/cve-2026-59691-gstreamer-rfbsrc-heap-buffer-overflow-in-hextile-decoding"},{"cve":"CVE-2026-14935","cvss":3.7,"slug":"cve-2026-14935-gstreamer-webrtcbin-logic-error-in-sdp-fingerprint-validation","title":"GStreamer webrtcbin logic error in SDP fingerprint validation","severity":"low","exploited":false,"published_at":"2026-07-07T16:16:38.01+00:00","url":"https://junglewise.ai/threats/cve-2026-14935-gstreamer-webrtcbin-logic-error-in-sdp-fingerprint-validation"},{"cve":"CVE-2026-12892","cvss":4.4,"slug":"cve-2026-12892-gstreamer-gst-plugins-bad-heap-out-of-bounds-read-in-h-264-parser","title":"GStreamer gst-plugins-bad heap out-of-bounds read in H.264 parser","severity":"medium","exploited":false,"published_at":"2026-06-23T21:16:55.07+00:00","url":"https://junglewise.ai/threats/cve-2026-12892-gstreamer-gst-plugins-bad-heap-out-of-bounds-read-in-h-264-parser"},{"cve":"CVE-2026-12891","cvss":4.3,"slug":"cve-2026-12891-gstreamer-gst-plugins-bad-out-of-bounds-read-in-h-266-parser","title":"GStreamer gst-plugins-bad out-of-bounds read in H.266 parser","severity":"medium","exploited":false,"published_at":"2026-06-23T21:16:54.947+00:00","url":"https://junglewise.ai/threats/cve-2026-12891-gstreamer-gst-plugins-bad-out-of-bounds-read-in-h-266-parser"},{"cve":"CVE-2026-53704","cvss":7.1,"slug":"cve-2026-53704-gstreamer-realmedia-demuxer-out-of-bounds-read-in-fileinfo","title":"GStreamer RealMedia demuxer out-of-bounds read in FILEINFO metadata","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:33.697+00:00","url":"https://junglewise.ai/threats/cve-2026-53704-gstreamer-realmedia-demuxer-out-of-bounds-read-in-fileinfo"},{"cve":"CVE-2026-53703","cvss":7.1,"slug":"cve-2026-53703-gstreamer-realmedia-demuxer-out-of-bounds-read-in-mdpr-chunk","title":"GStreamer RealMedia demuxer out-of-bounds read in MDPR chunk parsing","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:33.563+00:00","url":"https://junglewise.ai/threats/cve-2026-53703-gstreamer-realmedia-demuxer-out-of-bounds-read-in-mdpr-chunk"},{"cve":"CVE-2026-52722","cvss":7.1,"slug":"cve-2026-52722-gstreamer-vmnc-decoder-signed-integer-overflow-in-cursor-handling","title":"GStreamer VMnc decoder signed integer overflow in cursor handling","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:32.83+00:00","url":"https://junglewise.ai/threats/cve-2026-52722-gstreamer-vmnc-decoder-signed-integer-overflow-in-cursor-handling"},{"cve":"CVE-2026-52721","cvss":5.3,"slug":"cve-2026-52721-gstreamer-out-of-bounds-read-in-pcapparse-element","title":"GStreamer out-of-bounds read in pcapparse element","severity":"medium","exploited":false,"published_at":"2026-06-15T20:16:32.7+00:00","url":"https://junglewise.ai/threats/cve-2026-52721-gstreamer-out-of-bounds-read-in-pcapparse-element"},{"cve":"CVE-2026-52720","cvss":8.8,"slug":"cve-2026-52720-gstreamer-librfb-heap-buffer-overflow-in-vnc-rectangle-decoding","title":"GStreamer librfb heap buffer overflow in VNC rectangle decoding","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:32.58+00:00","url":"https://junglewise.ai/threats/cve-2026-52720-gstreamer-librfb-heap-buffer-overflow-in-vnc-rectangle-decoding"},{"cve":"CVE-2026-52719","cvss":7.1,"slug":"cve-2026-52719-gstreamer-gst-plugins-bad-out-of-bounds-read-in-va-jpeg-decoder","title":"GStreamer gst-plugins-bad out-of-bounds read in VA JPEG decoder","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:32.447+00:00","url":"https://junglewise.ai/threats/cve-2026-52719-gstreamer-gst-plugins-bad-out-of-bounds-read-in-va-jpeg-decoder"},{"cve":"CVE-2026-52718","cvss":6.5,"slug":"cve-2026-52718-gstreamer-gst-plugins-bad-denial-of-service-in-av1-codec-parser","title":"GStreamer gst-plugins-bad denial of service in AV1 codec parser","severity":"medium","exploited":false,"published_at":"2026-06-15T20:16:32.317+00:00","url":"https://junglewise.ai/threats/cve-2026-52718-gstreamer-gst-plugins-bad-denial-of-service-in-av1-codec-parser"},{"cve":"CVE-2026-3086","cvss":7.8,"epss":0.0038,"slug":"cve-2026-3086-gstreamer-h-266-codec-parser-out-of-bounds-write-in-aps-units","title":"GStreamer H.266 Codec Parser out-of-bounds write in APS units","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.767+00:00","url":"https://junglewise.ai/threats/cve-2026-3086-gstreamer-h-266-codec-parser-out-of-bounds-write-in-aps-units"},{"cve":"CVE-2026-3085","cvss":8.8,"epss":0.0054,"slug":"cve-2026-3085-gstreamer-heap-overflow-in-rtpqdm2depay-element","title":"GStreamer heap overflow in rtpqdm2depay element","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.62+00:00","url":"https://junglewise.ai/threats/cve-2026-3085-gstreamer-heap-overflow-in-rtpqdm2depay-element"},{"cve":"CVE-2026-3084","cvss":7.8,"epss":0.0038,"slug":"cve-2026-3084-gstreamer-h-266-codec-parser-integer-underflow-in-picture","title":"GStreamer H.266 Codec Parser integer underflow in picture partitions","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.477+00:00","url":"https://junglewise.ai/threats/cve-2026-3084-gstreamer-h-266-codec-parser-integer-underflow-in-picture"},{"cve":"CVE-2026-3083","cvss":8.8,"epss":0.0076,"slug":"cve-2026-3083-gstreamer-rtpqdm2depay-out-of-bounds-write-in-x-qdm-rtp-parsing","title":"GStreamer rtpqdm2depay out-of-bounds write in X-QDM RTP parsing","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.327+00:00","url":"https://junglewise.ai/threats/cve-2026-3083-gstreamer-rtpqdm2depay-out-of-bounds-write-in-x-qdm-rtp-parsing"},{"cve":"CVE-2026-3082","cvss":7.8,"epss":0.0063,"slug":"cve-2026-3082-gstreamer-jpeg-parser-heap-overflow-in-huffman-table-processing","title":"GStreamer JPEG Parser heap overflow in Huffman table processing","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.19+00:00","url":"https://junglewise.ai/threats/cve-2026-3082-gstreamer-jpeg-parser-heap-overflow-in-huffman-table-processing"},{"cve":"CVE-2026-3081","cvss":7.8,"epss":0.0038,"slug":"cve-2026-3081-gstreamer-h-266-codec-parser-stack-based-buffer-overflow","title":"GStreamer H.266 codec parser stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.047+00:00","url":"https://junglewise.ai/threats/cve-2026-3081-gstreamer-h-266-codec-parser-stack-based-buffer-overflow"},{"cve":"CVE-2026-2923","cvss":7.8,"epss":0.0065,"slug":"cve-2026-2923-gstreamer-out-of-bounds-write-in-dvb-subtitles-handling","title":"GStreamer out-of-bounds write in DVB Subtitles handling","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:33.013+00:00","url":"https://junglewise.ai/threats/cve-2026-2923-gstreamer-out-of-bounds-write-in-dvb-subtitles-handling"}],"vendor":{"hub":true,"name":"Gstreamer","slug":"gstreamer","homepage":"https://gstreamer.freedesktop.org/","description":"An open-source multimedia framework for creating streaming media applications.","url":"https://junglewise.ai/threats/vendors/gstreamer"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2016-9636","cvss":9.8,"slug":"cve-2016-9636-gstreamer-heap-buffer-overflow-in-flic-decoder","title":"GStreamer heap buffer overflow in FLIC decoder","severity":"critical","exploited":false,"published_at":"2017-01-27T22:59:02.053+00:00","url":"https://junglewise.ai/threats/cve-2016-9636-gstreamer-heap-buffer-overflow-in-flic-decoder"},{"cve":"CVE-2016-9635","cvss":9.8,"slug":"cve-2016-9635-gstreamer-heap-buffer-overflow-in-flic-decoder","title":"GStreamer heap buffer overflow in FLIC decoder","severity":"critical","exploited":false,"published_at":"2017-01-27T22:59:01.99+00:00","url":"https://junglewise.ai/threats/cve-2016-9635-gstreamer-heap-buffer-overflow-in-flic-decoder"},{"cve":"CVE-2016-9634","cvss":9.8,"slug":"cve-2016-9634-gstreamer-heap-buffer-overflow-in-flic-decoder","title":"GStreamer heap buffer overflow in FLIC decoder","severity":"critical","exploited":false,"published_at":"2017-01-27T22:59:01.943+00:00","url":"https://junglewise.ai/threats/cve-2016-9634-gstreamer-heap-buffer-overflow-in-flic-decoder"},{"cve":"CVE-2026-3083","cvss":8.8,"epss":0.0076,"slug":"cve-2026-3083-gstreamer-rtpqdm2depay-out-of-bounds-write-in-x-qdm-rtp-parsing","title":"GStreamer rtpqdm2depay out-of-bounds write in X-QDM RTP parsing","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.327+00:00","url":"https://junglewise.ai/threats/cve-2026-3083-gstreamer-rtpqdm2depay-out-of-bounds-write-in-x-qdm-rtp-parsing"},{"cve":"CVE-2026-3085","cvss":8.8,"epss":0.0054,"slug":"cve-2026-3085-gstreamer-heap-overflow-in-rtpqdm2depay-element","title":"GStreamer heap overflow in rtpqdm2depay element","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:46.62+00:00","url":"https://junglewise.ai/threats/cve-2026-3085-gstreamer-heap-overflow-in-rtpqdm2depay-element"},{"cve":"CVE-2026-52720","cvss":8.8,"slug":"cve-2026-52720-gstreamer-librfb-heap-buffer-overflow-in-vnc-rectangle-decoding","title":"GStreamer librfb heap buffer overflow in VNC rectangle decoding","severity":"high","exploited":false,"published_at":"2026-06-15T20:16:32.58+00:00","url":"https://junglewise.ai/threats/cve-2026-52720-gstreamer-librfb-heap-buffer-overflow-in-vnc-rectangle-decoding"},{"cve":"CVE-2025-47219","cvss":8.1,"slug":"cve-2025-47219-gstreamer-isomp4-plugin-out-of-bounds-read-in-qtdemux-parse-trak","title":"GStreamer isomp4 plugin out-of-bounds read in qtdemux_parse_trak","severity":"high","exploited":false,"published_at":"2025-08-07T20:15:27.627+00:00","url":"https://junglewise.ai/threats/cve-2025-47219-gstreamer-isomp4-plugin-out-of-bounds-read-in-qtdemux-parse-trak"},{"cve":"CVE-2026-2921","cvss":7.8,"epss":0.0084,"slug":"cve-2026-2921-gstreamer-riff-palette-integer-overflow-in-avi-handling","title":"GStreamer RIFF palette integer overflow in AVI handling","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:32.73+00:00","url":"https://junglewise.ai/threats/cve-2026-2921-gstreamer-riff-palette-integer-overflow-in-avi-handling"},{"cve":"CVE-2026-2920","cvss":7.8,"epss":0.0069,"slug":"cve-2026-2920-gstreamer-heap-overflow-in-asf-demuxer","title":"GStreamer heap overflow in ASF demuxer","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:31.637+00:00","url":"https://junglewise.ai/threats/cve-2026-2920-gstreamer-heap-overflow-in-asf-demuxer"},{"cve":"CVE-2026-2923","cvss":7.8,"epss":0.0065,"slug":"cve-2026-2923-gstreamer-out-of-bounds-write-in-dvb-subtitles-handling","title":"GStreamer out-of-bounds write in DVB Subtitles handling","severity":"high","exploited":false,"published_at":"2026-03-16T14:19:33.013+00:00","url":"https://junglewise.ai/threats/cve-2026-2923-gstreamer-out-of-bounds-write-in-dvb-subtitles-handling"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"GStreamer","slug":"gstreamer","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/gstreamer"},{"name":"Gstreamer Gst-Plugins-Bad","slug":"gst-plugins-bad","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/gst-plugins-bad"},{"name":"Gstreamer Gst-Plugins-Ugly","slug":"gst-plugins-ugly","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/gst-plugins-ugly"}]}