Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gstreamer

First CVE: Feb 2, 2009Active for: 17 yearsTotal CVEs: 112
53.9
VTI Score
TOP TARGET

GStreamer is a multimedia streaming framework embedded across a broad range of media players, content-delivery systems, and audio-video applications, despite its narrow product portfolio. The vendor's vulnerability footprint skews strongly toward critical-severity outcomes, reflecting the memory-safety demands and parsing complexity inherent to a C-based codec and container-handling pipeline. Exposure recurs consistently across the core GStreamer library and associated plugin suites—particularly Good Plug-ins and the general plugin ecosystem—through weakness classes including out-of-bounds reads and writes, integer overflows, heap-based buffer overflows, and NULL-pointer dereferences that are characteristic of low-level media processing code. Defenders should treat GStreamer disclosures as high-priority across all downstream products that bundle the library, since a single vulnerability can propagate across media applications, browsers, and embedded systems that depend on it. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
112
Total CVEs
More Total CVEs than 99% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gstreamer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2009
17 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (112 CVEs).

112 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-3083HIGH
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GS
Mar 13, 20268.833NONO
CVE-2026-3085HIGH
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation
Mar 13, 20268.833NONO
CVE-2026-46470CRITICAL
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate a
May 14, 20269.131NONO
CVE-2026-2921HIGH
GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStre
Mar 13, 20267.830NONO
CVE-2026-3082HIGH
GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Mar 13, 20267.830NONO
CVE-2026-2922HIGH
GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Mar 13, 20267.830NONO
CVE-2026-2920HIGH
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Mar 13, 20267.830NONO
CVE-2024-47615CRITICAL
GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The
Dec 12, 20249.830NONO
CVE-2026-3084HIGH
GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o
Mar 13, 20267.829NONO
CVE-2026-3086HIGH
GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Mar 13, 20267.829NONO
View all 112 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products112 CVEs
18%
64%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local37 (33.0%)
Network68 (60.7%)
Unknown7 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low100 (89.3%)
High5 (4.5%)
Unknown7 (6.3%)
User Interaction
None53 (47.3%)
Unknown7 (6.3%)
Required52 (46.4%)
Privileges Required
Low4 (3.6%)
High0 (0.0%)
None101 (90.2%)
Unknown7 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (112 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gstreamer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gstreamer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gstreamer's Products

View all 8 CNAs →

Top CWEs