GStreamer Project maintains a multimedia framework and streaming pipeline library embedded across audio, video, and media processing applications, with its vulnerability exposure centered on the core framework and related plug-in collections such as GStreamer Good Plug-ins and the RTSP server component. The observed weakness classes reflect the framework's C-based implementation and stream-handling complexity, with recurring issues around NULL-pointer dereference conditions and improper return-value validation in parsing and media-handling code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gstreamer Project over time
Signals from CVEs in this vendor scope (112 CVEs).
112 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3083HIGH GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GS | Mar 13, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-3085HIGH GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Mar 13, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-46470CRITICAL An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate a | May 14, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-2921HIGH GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStre | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-3082HIGH GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-2922HIGH GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-2920HIGH GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2024-47615CRITICAL GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The | Dec 12, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-3084HIGH GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o | Mar 13, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-3086HIGH GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Mar 13, 2026 | 7.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (112 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gstreamer Project.
Media articles that mention a CVE ID that affects a product developed by Gstreamer Project — matched by CVE ID, not by vendor name.