CVE-2026-14935Low· 3.7▾ SunlitA logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attrib…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.2%
A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.
gstreamer1-plugins-bad-free (all versions)gstreamer-plugins-bad-free (all versions)gstreamer1-plugins-bad-free (all versions)gstreamer-plugins-bad-free (all versions)gstreamer1-plugins-bad-free (all versions)gstreamer1-plugins-bad-free (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
There is no complete mitigation for this vulnerability. The following measures can reduce risk:
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12891Medium· 4.3Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser
CVE-2026-19387High· 7.6A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio
CVE-2026-59692High· 7.5A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin
CVE-2026-59691High· 7.1A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin
CVE-2026-94640High· 7.5Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service
CVE-2026-90462Medium· 5.4Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization