Ossrs maintains the Simple Realtime Server, a narrowly focused streaming and real-time communication platform whose vulnerability footprint centers on input-handling weaknesses at the application layer, particularly cross-site scripting, command injection, and OS command injection vulnerabilities. These weakness classes reflect the product's role in processing and relaying untrusted data streams and command-line inputs from clients and upstream sources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ossrs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34105HIGH SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vul | Jun 12, 2023 | 7.5 | 35 | NO | YES |
CVE-2024-29882MEDIUM SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint didn't filter the callback function name which led to injectin | Mar 28, 2024 | 6.1 | 26 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ossrs.
Media articles that mention a CVE ID that affects a product developed by Ossrs — matched by CVE ID, not by vendor name.