---
id: CVE-2026-14935
title: >-
  Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without
  a=fingerprint due to inverted presence check
summary: >-
  A logic vulnerability was found in GStreamer's webrtcbin component. The
  _check_sdp_crypto() function contains an inverted boolean condition that
  causes it to accept remote SDP offers or answers that lack the required
  a=fingerprint attrib…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-670
vendor: Red Hat
product: gstreamer1-plugins-bad-free
affected:
  - gstreamer1-plugins-bad-free (all versions)
  - gstreamer-plugins-bad-free (all versions)
  - gstreamer1-plugins-bad-free (all versions)
  - gstreamer-plugins-bad-free (all versions)
  - gstreamer1-plugins-bad-free (all versions)
  - gstreamer1-plugins-bad-free (all versions)
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-07T16:13:21.634704Z'
published: '2026-07-07'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T17:27:23.306Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-14935'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-14935'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2497679'
    label: RHBZ#2497679
  - url: >-
      https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/98
  - url: 'https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5171'
tags:
  - cve.org
epss: 0.00233
epssPercentile: 0.14421
ingestedAt: '2026-09-11T11:32:42.885Z'
---

## Overview

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.

## Affected

- `gstreamer1-plugins-bad-free (all versions)`
- `gstreamer-plugins-bad-free (all versions)`
- `gstreamer1-plugins-bad-free (all versions)`
- `gstreamer-plugins-bad-free (all versions)`
- `gstreamer1-plugins-bad-free (all versions)`
- `gstreamer1-plugins-bad-free (all versions)`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

### Workarounds

There is no complete mitigation for this vulnerability. The following measures can reduce risk:

1. Ensure WebRTC signaling channels use TLS encryption to prevent SDP modification in transit.
2. If WebRTC functionality is not required, remove the webrtcbin plugin shared object from the GStreamer plugins directory (typically /usr/lib64/gstreamer-1.0/libgstwebrtc.so).
