OSSRS SRS (Simple Realtime Server) versions earlier than 5.0.213 contain a remote code execution vulnerability in RTMP publish-authorization handling associated with vhost-level security configuration. The flaw involves processing performed by the SRS security check and RTMP listener components when vhost security is enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a focused PoC and supporting documentation for CVE-2026-68004, an OSSRS/SRS insecure-default / missing-authentication issue allowing unauthenticated RTMP publish when vhost.security is disabled and no alternate publish auth is enforced. Structure is minimal: one Python exploit script, one README, and one detailed technical report. The main exploit file, poc_srs_unauth_publish.py, is a standalone Python 3 script using only the standard library. It implements a minimal RTMP client: resolves the target host, opens a TCP connection, performs the RTMP handshake (C0/C1/S0/S1/S2/C2), sends a chunk-size message, then issues AMF0-encoded connect, createStream, and publish commands. It determines success by parsing printable strings from server responses and checking for NetConnection.Connect.Success followed by NetStream.Publish.Start. This demonstrates that the server accepted an unauthenticated publish request. The script briefly holds the socket open after success so operators can observe the stream state. A secondary capability is optional HTTP API probing via --check-api. The script sends unauthenticated HTTP requests to common SRS API endpoints (/api/v1/versions, /api/v1/summaries, /api/v1/streams/, /api/v1/clients/) on port 1985 and records whether they appear accessible without auth. This does not exploit the RTMP flaw directly but helps assess related exposure. Operationally, the exploit is best classified as OPERATIONAL rather than a simple POC because it contains complete protocol logic and a working verification path, but it does not deliver arbitrary code execution or a customizable post-exploitation payload. Its effect is unauthorized content injection / stream hijack validation against reachable SRS instances, primarily over network-accessible RTMP on 1935/tcp, with optional web/API exposure checks on 1985/tcp. The markdown report also discusses related exposure on 8080/tcp and references upstream SRS source/config files to explain the root cause.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.