{"id":"CVE-2026-14935","title":"Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check","summary":"A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attrib…","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cvssSource":"cna","cwe":["CWE-670"],"vendor":"Red Hat","product":"gstreamer1-plugins-bad-free","affected":["gstreamer1-plugins-bad-free (all versions)","gstreamer-plugins-bad-free (all versions)","gstreamer1-plugins-bad-free (all versions)","gstreamer-plugins-bad-free (all versions)","gstreamer1-plugins-bad-free (all versions)","gstreamer1-plugins-bad-free (all versions)"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-07T16:13:21.634704Z"},"published":"2026-07-07","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:27:23.306Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-14935","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-14935"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497679","label":"RHBZ#2497679"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/98"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171"}],"tags":["cve.org"],"epss":0.00233,"epssPercentile":0.14395,"ingestedAt":"2026-09-11T11:32:42.885Z","slug":"CVE-2026-14935","body":"## Overview\n\nA logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.\n\n## Affected\n\n- `gstreamer1-plugins-bad-free (all versions)`\n- `gstreamer-plugins-bad-free (all versions)`\n- `gstreamer1-plugins-bad-free (all versions)`\n- `gstreamer-plugins-bad-free (all versions)`\n- `gstreamer1-plugins-bad-free (all versions)`\n- `gstreamer1-plugins-bad-free (all versions)`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nThere is no complete mitigation for this vulnerability. The following measures can reduce risk:\n\n1. Ensure WebRTC signaling channels use TLS encryption to prevent SDP modification in transit.\n2. If WebRTC functionality is not required, remove the webrtcbin plugin shared object from the GStreamer plugins directory (typically /usr/lib64/gstreamer-1.0/libgstwebrtc.so).","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}