CVE-2026-68004
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srsappsecurity.cpp, and SRS RTMP listener components
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ossrs/srs/releases/tag/v5.0-r3, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68004.json, https://nvd.nist.gov/vuln/detail/CVE-2026-68004, https://github.com/xuwu-xuwu/CVE-2026-68004