Remote Code Execution Vulnerability in GStreamer Product by GStreamer
CVE-2026-18295
7.8HIGH
What is CVE-2026-18295?
A vulnerability in GStreamer allows remote attackers to execute arbitrary code via a crafted MRF file. The flaw stems from insufficient validation of user inputs during MRF file parsing, potentially leading to a buffer overflow. Exploiting this vulnerability requires user interaction, such as visiting a compromised website or opening a malicious file, which could have severe consequences for the security of affected systems.
Affected Version(s)
GStreamer 13fcb641ed33d1472e4ffdec2846180b15405053
