VDB

CVE-2026-2920

CVE-2026-2920 PUBLISHED CVSS 7.800000190734863 HIGH

Multiple critical RCE vulnerabilities have been identified in GStreamer, the open-source multimedia framework, disclosed on the 13 of March 2026. These flaws exist across multiple media parsers and demuxers, including ASF, RealMedia, DVB Subtitles, JPEG, RIFF, H.265 and H.266. They are caused by memory safety issues such as heap/stack buffer overflows, out-of-bounds writes, and integer overflows/underflows (CVSS 7.8). The two most severe flaws CVE-2026-3083 and CVE-2026-3085 (CVSS 8.8) reside in the rtpqdm2depay component and are remotely exploitable over the network via maliciously crafted RTP streams. All reported vulnerabilities have been patched in the latest GStreamer release and organizations are strongly advised to update immediately and restrict processing of untrusted media content.

EPSS 0.77% · 52.3th percentile

Risk Scores

CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.77%
52.3th percentile

Timeline

  • Feb 25, 2026 CVE Published
  • Mar 6, 2026 PoC Published
  • Mar 14, 2026 EPSS Score
  • Mar 15, 2026 EPSS Score
  • Mar 16, 2026 EPSS Score
  • Mar 16, 2026 PoC Published
  • Mar 17, 2026 EPSS Score
  • Mar 17, 2026 Coalition ESS Score
  • Mar 18, 2026 EPSS Score
  • Mar 18, 2026 PoC Published
  • Mar 19, 2026 EPSS Score
  • Mar 20, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›