Insertion of Sensitive Information Into Sent Data in gst-plugins-good and gstreamer - #VU147414
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of sensitive information during cross-origin redirects in the souphttpsrc HTTP source when automatically following cross-origin HTTP redirects. A remote attacker can redirect the request to an attacker-controlled endpoint to disclose sensitive information.
Exploitation requires an application to open an attacker-controlled initial HTTP location with credentials, cookies, or custom headers configured.
Affected software
gstreamer
Remediation
gstreamer - update to 1.28.7