GStreamer is a multimedia streaming framework embedded across a broad range of media players, content-delivery systems, and audio-video applications, despite its narrow product portfolio. The vendor's vulnerability footprint skews strongly toward critical-severity outcomes, reflecting the memory-safety demands and parsing complexity inherent to a C-based codec and container-handling pipeline. Exposure recurs consistently across the core GStreamer library and associated plugin suites—particularly Good Plug-ins and the general plugin ecosystem—through weakness classes including out-of-bounds reads and writes, integer overflows, heap-based buffer overflows, and NULL-pointer dereferences that are characteristic of low-level media processing code. Defenders should treat GStreamer disclosures as high-priority across all downstream products that bundle the library, since a single vulnerability can propagate across media applications, browsers, and embedded systems that depend on it. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gstreamer over time
Signals from CVEs in this vendor scope (112 CVEs).
112 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3083HIGH GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GS | Mar 13, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-3085HIGH GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Mar 13, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-46470CRITICAL An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate a | May 14, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-2921HIGH GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStre | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-3082HIGH GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-2922HIGH GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-2920HIGH GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2024-47615CRITICAL GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The | Dec 12, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-3084HIGH GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o | Mar 13, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-3086HIGH GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (112 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gstreamer.
Media articles that mention a CVE ID that affects a product developed by Gstreamer — matched by CVE ID, not by vendor name.