---
id: CVE-2026-18649
title: A flaw was found in the GStreamer gst-plugins-good package
summary: >-
  A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay
  and rtph265depay RTP depayloader elements do not enforce a maximum size limit
  on the reassembly buffer used during fragmented RTP packet processing. A
  remote, u…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Red Hat
product: gstreamer1-plugins-good
affected:
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
  - gstreamer1-plugins-good (all versions)
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
published: '2026-08-06'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T15:17:13.373'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18649'
references:
  - url: 'https://0xsemizzz.vercel.app/projects/cve-2026-18649-gstreamer-rtp-dos/'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53451'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53452'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56966'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:61588'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:61943'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65959'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65999'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69232'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70264'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70584'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70803'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18649'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510614'
    label: secalert@redhat.com
  - url: 'https://github.com/0xSemizzz/CVE-2026-18649'
    label: secalert@redhat.com
  - url: >-
      https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/113
    label: secalert@redhat.com
  - url: 'https://0xsemizzz.vercel.app/blog/cve-2026-18649-gstreamer-rtp-dos/'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18649.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18649'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18649'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-06T13:42:01.159055Z'
epss: 0.00961
epssPercentile: 0.59891
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/0xSemizzz/CVE-2026-18649'
  checkedAt: '2026-09-25T08:20:52.077Z'
exploitAvailable: true
ingestedAt: '2026-09-09T14:11:29.385Z'
---

## Overview

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:65959** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:65959)
- **RHSA-2026:53451** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53451)
- **RHSA-2026:56966** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:56966)
- **RHSA-2026:65999** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:65999)
- **RHSA-2026:61588** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61588)
- **RHSA-2026:61943** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:61943)
- **RHSA-2026:53452** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53452)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18649.json)
- **RHSA-2026:69232** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69232)
- **RHSA-2026:70264** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70264)
- **RHSA-2026:70584** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70584)
- **RHSA-2026:70803** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70803)
