membrane_mp4_plugin
MPEG-4 container plugin for Membrane Framework
Activity
- Latest release
- 2mo ago
- Total releases
- 63
- Cadence
- ~10 days
- Last 12 months
- 10
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Jun 04, 2020
| Version | Released | |
|---|---|---|
0.36.10
patch
|
0.36.10
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.9
patch
|
0.36.9
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.8
patch
|
0.36.8
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.7
patch
|
0.36.7
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.6
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.6
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.5
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.5
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.4
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.4
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.3
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.2
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.36.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.36.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.35.3
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.35.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.35.2
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.35.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.35.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.35.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.35.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.35.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.34.2
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.34.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.34.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.34.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.34.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.34.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.33.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.33.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.33.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.33.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.32.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.32.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.31.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.31.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.30.2
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.30.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.30.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.30.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.30.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.30.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.29.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.29.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.29.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.29.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.28.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.28.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.28.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.28.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.27.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.27.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.26.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.26.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.26.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.26.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.25.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.25.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.24.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.24.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.24.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.24.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.23.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.23.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.22.3
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.22.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.22.2
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.22.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.22.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.22.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.22.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.22.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.21.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.21.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.20.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.20.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.19.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.19.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.18.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.18.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.18.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.18.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.17.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.17.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
0.16.2
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.16.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
0.16.1
patch
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.16.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
0.16.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.16.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
0.15.0
minor
1 CVE
CVE-2026-53423
GHSA-43hj-fxwj-49qw
EEF-CVE-2026-53423
Aug 18, 2026
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Medium
Local
Low
None
None
Summary
DetailsThe MP4 container parser walks the input stream box-by-box. For each box, The fix replaces the unsafe interning with PoC
ImpactAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with References
Affected versions
0.10.0
0.11.0
0.12.0
0.12.1
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
+ 47 more Show less
0.18.1
0.19.0
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.24.1
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.30.1
0.30.2
0.31.0
0.32.0
0.33.0
0.33.1
0.34.0
0.34.1
0.34.2
0.35.0
0.35.1
0.35.2
0.35.3
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.36.5
0.36.6
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
Fixed in
0.36.7
References
Updated Aug 18, 2026 · Source: OSV.dev |
0.15.0
minor
Dependencies (7)
Changelog
Compare changes
|