CVE-2026-18649

HIGH

Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-18649. PoCs published by 0xSemizzz.

AI-analyzed exploit summary This PoC exploits a resource exhaustion vulnerability (CWE-770) in GStreamer's H.264 RTP depayloader (rtph264depay) by sending a stream of RTP fragments without the end-of-fragment bit, causing unbounded memory growth in the GstAdapter buffer until the process crashes.

Description

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

Exploits (1)

github WORKING POC 1 stars
by 0xSemizzz · pythonpoc
https://github.com/0xSemizzz/CVE-2026-18649

This PoC exploits a resource exhaustion vulnerability (CWE-770) in GStreamer's H.264 RTP depayloader (rtph264depay) by sending a stream of RTP fragments without the end-of-fragment bit, causing unbounded memory growth in the GstAdapter buffer until the process crashes.

Classification
Working Poc 99%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: GStreamer gst-plugins-good (rtph264depay/rtph265depay) versions prior to the fix for CVE-2026-18649 (confirmed on 1.28.2)
No auth needed
Prerequisites: Network access to the target GStreamer pipeline processing RTP/H.264 streams · GStreamer with rtph264depay plugin (gst-plugins-good) in the pipeline
mistral-large-3 · analyzed Aug 06, 2026 Full analysis →

References (3)

Core 3
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-18649
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2510614
https://bugzilla.redhat.com/show_bug.cgi?id=2510614

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (4)
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 8
Red Hat/Red Hat Enterprise Linux 9
Published Aug 06, 2026
Tracked Since Aug 06, 2026