CVE-2026-105486
Received Received - Intake

Authentication Bypass in OSSRS SRS

Vulnerability report for CVE-2026-105486, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OSSRS srs 7.0-a1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OSSRS srs up to version 7.0-a1. It involves a missing authentication check in the System API function systemAPI.Run located in internal/proxy/api.go. Attackers can remotely exploit this to register malicious backend servers without authentication, enabling stream hijacking and interception of media traffic.

Detection Guidance

Check if the SRS proxy System API on port 12025 is exposed to the network by running: netstat -tulnp | grep 12025 or ss -tulnp | grep 12025. Test unauthenticated access by sending a POST request to /api/v1/srs/register with a JSON payload like {"ip":"attacker_ip","port":1234,"vhost":"example.com"} using curl -X POST http://<target_ip>:12025/api/v1/srs/register -H "Content-Type: application/json" -d '{"ip":"attacker_ip","port":1234,"vhost":"example.com"}'.

Monitor logs for unexpected POST requests to /api/v1/srs/register or unusual media stream routing changes. Verify if Bearer token authentication is enforced by checking environment variables like SRS_HTTP_API_AUTH_TYPE.

Impact Analysis

An attacker could hijack media streams, intercept credentials, perform denial of service attacks, or launch SSRF attacks. The proxy routes all media requests to attacker-controlled hosts, compromising confidentiality and availability of streaming services.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive media streams, violating data protection requirements under GDPR and HIPAA. Non-compliance may result in legal penalties, reputational damage, and loss of trust due to unauthorized data exposure.

Mitigation Strategies

Upgrade SRS to version 8.0-d0 or later immediately. Disable unauthenticated access to the proxy System API by ensuring Bearer token authentication is enabled via SRS_HTTP_API_AUTH_TYPE. Block external access to port 12025 using firewall rules if not required.

Review and remove any unauthorized backend server registrations in the proxy configuration. Implement network segmentation to isolate media streaming components from untrusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105486. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart