An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srsappsecurity.cpp, and SRS RTMP listener components
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68004.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68004.json"
[
{
"target": {
"function": "SrsConfig::check_normal_config",
"file": "trunk/src/app/srs_app_config.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-16d8e81f",
"signature_version": "v1",
"digest": {
"length": 21594.0,
"function_hash": "226559195366240570613239547824494083073"
},
"signature_type": "Function"
},
{
"target": {
"function": "TEST",
"file": "trunk/src/utest/srs_utest_config.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-21244b17",
"signature_version": "v1",
"digest": {
"length": 2085.0,
"function_hash": "261274701916894594133095247393984650133"
},
"signature_type": "Function"
},
{
"target": {
"function": "SrsRtcFromRtmpBridge::initialize",
"file": "trunk/src/app/srs_app_rtc_source.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-22de651d",
"signature_version": "v1",
"digest": {
"length": 650.0,
"function_hash": "268409228914511413180013334703407640717"
},
"signature_type": "Function"
},
{
"target": {
"function": "SrsRtcFromRtmpBridge::filter",
"file": "trunk/src/app/srs_app_rtc_source.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-3c96451f",
"signature_version": "v1",
"digest": {
"length": 527.0,
"function_hash": "79825939864511838756582852559993745017"
},
"signature_type": "Function"
},
{
"target": {
"function": "SrsSample::SrsSample",
"file": "trunk/src/kernel/srs_kernel_codec.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-7b71e126",
"signature_version": "v1",
"digest": {
"length": 106.0,
"function_hash": "229841435328078950950655098281422813057"
},
"signature_type": "Function"
},
{
"target": {
"function": "SrsRtcFromRtmpBridge::SrsRtcFromRtmpBridge",
"file": "trunk/src/app/srs_app_rtc_source.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-7e9410ed",
"signature_version": "v1",
"digest": {
"length": 797.0,
"function_hash": "281571543077188217118031087209080364906"
},
"signature_type": "Function"
},
{
"target": {
"function": "SrsRtcFromRtmpBridge::package_nalus",
"file": "trunk/src/app/srs_app_rtc_source.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-9919bf76",
"signature_version": "v1",
"digest": {
"length": 2148.0,
"function_hash": "278052177231047553271532163714053220188"
},
"signature_type": "Function"
},
{
"target": {
"file": "trunk/src/app/srs_app_rtc_source.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-9960bd21",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"25271321213751360748383411939051072610",
"174652908441626715357816685046443072898",
"147734810499394600038222693512936216938",
"187543280301087329333730801699607935968",
"248176713005144118099747693454994380986",
"184576363058318462348446629510110409173",
"198934951167102937908158003036982350625",
"162619987521822828992784690565523903304",
"308196253658812501896273201296196899065",
"68688847229980601192310583740509291496",
"31681561318829404847985601101390264821",
"17261501035457065825375251857905513823",
"253734766166004444141270859380482049272",
"71812202342053698740673531692398011302",
"317441113538895897307572691472104579429",
"113953733634830481934295679750146981079",
"179733566763884384998247582923177086109",
"72838705096531907692661024358334336942",
"18324484384110025168596844805227865321",
"84592297565351452187244855689151172567",
"314578658494735668255242199795853504852",
"220133108601693855528216283793260415684",
"128413237212824229808780563594850549109",
"259991849299150773321450936803584095795",
"294296877637447866341905999991430763359",
"17201714094707122084491034222082164852",
"309296378903745656480588476866412760114",
"4281347624840760271454413392904630890",
"71812202342053698740673531692398011302",
"297746118317194600678713430206235887331",
"223689900595056645290050479011423348845",
"158417649147271182640030689004809589823"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "SrsSample::parse_bframe",
"file": "trunk/src/kernel/srs_kernel_codec.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-9f0bfe67",
"signature_version": "v1",
"digest": {
"length": 785.0,
"function_hash": "328741636716571139813595720484770742569"
},
"signature_type": "Function"
},
{
"target": {
"file": "trunk/src/app/srs_app_config.hpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-a3b8eea4",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"99286657027071436274411121432443314316",
"23561982493838460015173022723450619364",
"168909630008449305187191364759359717157",
"69294055959536755783328493886653086314"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "trunk/src/utest/srs_utest_config.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-bdf90650",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"258340889288545251658838189497335921296",
"319947025033415262077767862323608079100",
"266410820450682944316521252384925812194",
"195461833783363825282343569977588313382"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "trunk/src/app/srs_app_config.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-bf4b3923",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"302203375230591420413237705011689429993",
"53610064810974939496407003762646768188",
"337229342793045058508620254897301407918",
"16582856423101092372425995176257375400",
"324800173159808641698798442446249475610",
"59534318837487966802662204465975140975",
"229917039075811266716682291753110854815"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "SrsSample::SrsSample",
"file": "trunk/src/kernel/srs_kernel_codec.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-c7dcc37a",
"signature_version": "v1",
"digest": {
"length": 73.0,
"function_hash": "116013864838940626301190954180507623065"
},
"signature_type": "Function"
},
{
"target": {
"function": "SrsFrame::add_sample",
"file": "trunk/src/kernel/srs_kernel_codec.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-d1c7b056",
"signature_version": "v1",
"digest": {
"length": 372.0,
"function_hash": "188245877718034884714892091805896549368"
},
"signature_type": "Function"
},
{
"target": {
"file": "trunk/src/app/srs_app_rtc_source.hpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-d8352669",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"52183804196467689517984931244388929136",
"69760871713596516329158184321091950094",
"305169745792949917232655321691425349336",
"174698216169856835578398274186366958150"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "SrsSample::copy",
"file": "trunk/src/kernel/srs_kernel_codec.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-decc1dd0",
"signature_version": "v1",
"digest": {
"length": 141.0,
"function_hash": "36832145740882143406671710345471204705"
},
"signature_type": "Function"
},
{
"target": {
"file": "trunk/src/kernel/srs_kernel_codec.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-e17582c4",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"184544963730438786486515489251509157381",
"222135317469249829656235614687908921191",
"99827822765419657872064346522846729817",
"251135245442862946421089380397465393112",
"124164544403042443708785507947982818068",
"257408146481154438699533217910770356672",
"24355563729944140937970063878115720251",
"258136301921105958215385489523832217786",
"101884771951224902070696723076391464367",
"192533140333100334691029251772441782782",
"169170746251919474825305810214930976853",
"30686261462686848703215306848149866267",
"235803867329211809022380931960309730386",
"117537367344764024632155387176368225824",
"315152007675083891824268822636505633032",
"27667980487531521818683146088273831442",
"142859934386187619489832998252450190305",
"213939242239847340981543630015403187205",
"29609649188600622055615974660209797725",
"72214154578633538346075785234702680125",
"209453429504788523327246227985684483482",
"201815055261563394721911183803134983057",
"228401520195154093724610984269232917864",
"80081871027806530216177696326094708950",
"96213837037585904276970961797879609981",
"165224918235219768120257243504611005960",
"297836202184631115406943678517772433346",
"152313602383401682919044234730960490983",
"99808081118961102796493249048536566641",
"85688838750251872183213508018215629965",
"110726377619278584208901046378076469336",
"60983996593322764244570911147663102613",
"333592444888173875226341437599657404297",
"173397577412534333983092713196596671956",
"255437440325800629875154155777527606983",
"283441853050846524384873593137729169163",
"55593269552365865470083347528771827923",
"270569978840784887579575500647026138994",
"299547038795949985866965154427122714755",
"155833803341642047716903790646427533817",
"333811600525402875359655756525211193194",
"149569282492684354651697259556324297362",
"115565068466684701275143188405691959314",
"166621124810855697743166303377624516139",
"70432767786483207058925956948565790325",
"278704700724267448468726240308019275415",
"52586474576112472299883255017807270577",
"250078638304339533800409258715668074684",
"280201013561317730259902975330611603449",
"14863531779988774683033580278735433293",
"141947901764457983074518278772772653701",
"321478425348457901859248806100424497411",
"331336895820545944929711771489536468686",
"87141408319663909170010697182788476923"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "trunk/src/kernel/srs_kernel_error.hpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-e6702760",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"170676723871695846641027016812986215254",
"113930517694594751113705258481685393332",
"240162307878491751138607458755763894289",
"306570819901783400930428913196289704885"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "SrsRtcFromRtmpBridge::on_video",
"file": "trunk/src/app/srs_app_rtc_source.cpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-e888ace0",
"signature_version": "v1",
"digest": {
"length": 1648.0,
"function_hash": "7866412636726132066727155338193418996"
},
"signature_type": "Function"
},
{
"target": {
"file": "trunk/src/kernel/srs_kernel_codec.hpp"
},
"deprecated": false,
"source": "https://github.com/ossrs/srs/commit/313913737f13f97d9816dbc3d729e7bcd454a531",
"id": "CVE-2026-68004-fdc86b84",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"191506057807305023726737529869259988313",
"157293663800191152429004848735714187494",
"222777036519578606516113782455404277505",
"24367416837424289234868164185854721411",
"280094679461015718504266768151577125389",
"146981694207173264604802352907743140724",
"103314646820069069379893048418514041316",
"147817838937576180853535470053636699004",
"78162865917919206368060452256286880130",
"144036696189361967888763939323509773836",
"90498882162838011206047656433009044859",
"137211455241026750005278346899180957203",
"226322833196395697649693407704062066305",
"312244723958109799607203732055131695645",
"290705447586655715719660003767589388601",
"154239545883414663422251145335020679528",
"68998605377517843640033865390679189693"
]
},
"signature_type": "Line"
}
]
"2026-08-20T10:17:21Z"