CVE-2024-29882: Ossrs Simple Realtime Server

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint didn't filter the callback function name which led to injecting malicious javascript payloads and executing XSS ( Cross-Site Scripting). This vulnerability is fixed in 5.0.210 and 6.0.121.

Affected products

  • Ossrs Simple Realtime Server: before 5.0.210 (fixed in 5.0.210); from 6.0.0, before 6.0.121 (fixed in 6.0.121)

Published 2024-03-28. Last modified 2026-06-17.