Security Advisory SRT Protocol Library Vulnerabilities

  • Advisory ID: AJA-SA-2026-002
  • Publish Date: July 24, 2026
  • Last Updated: August 20, 2026
  • Severity: Critical
  • CVSS v3.1 Score: 9.1 / 10 (both CVEs)
  • Status: HELO Plus fixed in firmware v2.1.6; BRIDGE LIVE, BRIDGE LIVE 12G-4 and BRIDGE LIVE 3G-8 fixed in software v1.20.3; BRIDGE LIVE IP patch in development

Summary

The SRT Alliance has disclosed two critical vulnerabilities in the open-source SRT (Secure Reliable Transport) protocol library, versions 1.5.5 and earlier. Both vulnerabilities are remotely exploitable, require no authentication, and are rated CVSS 9.1 (Critical).

CVE Title
CVE-2026-55869 Heap-Based Buffer Overflow in KMREQ Handling
CVE-2026-55868 Encryption State Machine Downgrade

These vulnerabilities affect the following AJA products:

Product Affected Versions Status
HELO Plus Firmware prior to v2.1.6 Fixed in firmware v2.1.6 (released August 4, 2026)
BRIDGE LIVE Software prior to v1.20.3 Fixed in software v1.20.3 (released August 20, 2026)
BRIDGE LIVE 12G-4 Software prior to v1.20.3 Fixed in software v1.20.3 (released August 20, 2026)
BRIDGE LIVE 3G-8 Software prior to v1.20.3 Fixed in software v1.20.3 (released August 20, 2026)
BRIDGE LIVE IP Versions using SRT library v1.5.5 or earlier Patch in development

AJA is treating these as actively exploitable. Fixes are available now for HELO Plus in firmware v2.1.6 and for BRIDGE LIVE, BRIDGE LIVE 12G-4 and BRIDGE LIVE 3G-8 in software v1.20.3. A patch for BRIDGE LIVE IP is still in development. This advisory will be updated as further remediation becomes available.

For full technical and vulnerability detail from the protocol maintainers, see the official SRT Alliance announcement: https://srtalliance.org/srt-alliance-security-advisory/.

Recommended Immediate Mitigations

Until a device is running patched software, apply these mitigations to reduce exposure:

  • Restrict access to SRT listening ports to known, trusted source IPs using firewall or security group rules. This blocks the primary attack path for both CVEs.
  • Route SRT traffic over private connectivity (VPN, private WAN, dedicated links) rather than the public internet.
  • Avoid exposing SRT listener ports directly to untrusted or public networks.
  • Monitor affected devices for unexpected crashes, restarts, or encryption-state changes on active SRT sessions, which may indicate exploitation attempts.
  • Segment SRT endpoints on isolated network zones where possible, to limit exposure even from other internal hosts.

These mitigations meaningfully reduce risk but do not eliminate it. Patching remains the only complete remediation.

AJA Remediation Status

HELO Plus - Fixed

HELO Plus firmware v2.1.6, released August 4, 2026, incorporates the fixed SRT library (v1.5.6 or later) and resolves both CVEs. All HELO Plus units running firmware prior to v2.1.6 are affected, and AJA strongly recommends updating immediately.

Firmware v2.1.6 and its release notes are available on the HELO Plus v2.1.6 download page, or from the Support tab of the HELO Plus product page.

BRIDGE LIVE, BRIDGE LIVE 12G-4 and BRIDGE LIVE 3G-8 - Fixed

BRIDGE LIVE software v1.20.3, released August 20, 2026, incorporates SRT library v1.5.6 and resolves both CVEs on BRIDGE LIVE, BRIDGE LIVE 12G-4 and BRIDGE LIVE 3G-8. All units running software prior to v1.20.3 are affected, and AJA strongly recommends updating immediately.

Software v1.20.3 is available on the BRIDGE LIVE Software v1.20.3 download page, or from the Support tab of the BRIDGE LIVE product page. See the v1.20.3 release notes for full details.

BRIDGE LIVE IP - Patch in Development

AJA is actively developing a patch for BRIDGE LIVE IP to incorporate the fixed SRT library. This advisory will be updated with:

  • Target release dates for patched software
  • Upgrade instructions
  • Confirmation of testing/validation

BRIDGE LIVE IP customers are strongly encouraged to apply the immediate mitigations above while the patch is finalized.

References

Revision History

Date Change
August 20, 2026 BRIDGE LIVE software v1.20.3 released, resolving both CVEs on BRIDGE LIVE, BRIDGE LIVE 12G-4 and BRIDGE LIVE 3G-8. BRIDGE LIVE IP patch still in development.
August 4, 2026 HELO Plus firmware v2.1.6 released, resolving both CVEs. BRIDGE LIVE patch still in development.
July 24, 2026 Initial publication.

Contact

For questions regarding this advisory or assistance with mitigation, contact security@aja.com.

This advisory will be updated as new information becomes available.