An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 20:16
Updated : 2026-09-09 16:04
NVD link : CVE-2026-68004
Mitre link : CVE-2026-68004
CVE.ORG link : CVE-2026-68004
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
