Gstreamer · Gstreamer · CVE-2026-14935
**Name of the Vulnerable Software and Affected Versions**
GStreamer (affected versions not specified)
**Description**
A logic issue exists in the `webrtcbin` component. The ` check sdp crypto()` function uses an inverted boolean condition, leading the system to accept remote Session Description Protocol (SDP) offers or answers that miss the mandatory `a=fingerprint` attribute, while rejecting those that correctly include it. An attacker capable of intercepting and modifying WebRTC signaling messages can bypass the SDP-level Datagram Transport Layer Security (DTLS) certificate fingerprint binding, which reduces protection against man-in-the-middle attacks on media streams.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.