PatchSiren

OSSRS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL OSSRS CVE published 2026-08-17

CVE-2026-68004

A critical vulnerability in OSSRS SRS (Simple Realtime Server) versions prior to v5.0.213 can allow remote attackers to execute arbitrary code via RTMP publish authorization. This issue is due to a problem with vhost-level security configuration (security.enabled) and SrsSecurity::check() in trunk/src/app/srs_app_security.cpp and SRS RTMP listener components.