USN-8764-1: SRT vulnerabilities
It was discovered that SRT did not authenticate certain encryption control
messages. A remote attacker could possibly use this issue to downgrade an
encrypted connection and inject arbitrary content or interrupt a media
stream. (CVE-2026-55868)
It was discovered that SRT did not properly validate certain control
packets during connection setup and key refresh operations. A remote
attacker could possibly use this issue to cause SRT to crash, resulting in
a denial of service. (CVE-2026-55869)