Security Advisory SRT Protocol Library Vulnerabilities

  • Advisory ID: AJA-SA-2026-002
  • Publish Date: July 24, 2026
  • Last Updated: August 4, 2026
  • Severity: Critical
  • CVSS v3.1 Score: 9.1 / 10 (both CVEs)
  • Status: HELO Plus fixed in firmware v2.1.6; BRIDGE LIVE patch in development

Summary

The SRT Alliance has disclosed two critical vulnerabilities in the open-source SRT (Secure Reliable Transport) protocol library, versions 1.5.5 and earlier. Both vulnerabilities are remotely exploitable, require no authentication, and are rated CVSS 9.1 (Critical).

CVE Title
CVE-2026-55869 Heap-Based Buffer Overflow in KMREQ Handling
CVE-2026-55868 Encryption State Machine Downgrade

These vulnerabilities affect the following AJA products:

Product Affected Versions Status
HELO Plus Firmware prior to v2.1.6 Fixed in firmware v2.1.6 (released August 4, 2026)
BRIDGE LIVE Versions using SRT library v1.5.5 or earlier Patch in development
BRIDGE LIVE 12G-4 Versions using SRT library v1.5.5 or earlier Patch in development
BRIDGE LIVE 3G-8 Versions using SRT library v1.5.5 or earlier Patch in development
BRIDGE LIVE IP Versions using SRT library v1.5.5 or earlier Patch in development

AJA is treating these as actively exploitable. A fix for HELO Plus is available now in firmware v2.1.6, and a BRIDGE LIVE patch is in development. This advisory will be updated as further remediation becomes available.

For full technical and vulnerability detail from the protocol maintainers, see the official SRT Alliance announcement: https://srtalliance.org/srt-alliance-security-advisory/.

Recommended Immediate Mitigations

Until a device is running patched software, apply these mitigations to reduce exposure:

  • Restrict access to SRT listening ports to known, trusted source IPs using firewall or security group rules. This blocks the primary attack path for both CVEs.
  • Route SRT traffic over private connectivity (VPN, private WAN, dedicated links) rather than the public internet.
  • Avoid exposing SRT listener ports directly to untrusted or public networks.
  • Monitor affected devices for unexpected crashes, restarts, or encryption-state changes on active SRT sessions, which may indicate exploitation attempts.
  • Segment SRT endpoints on isolated network zones where possible, to limit exposure even from other internal hosts.

These mitigations meaningfully reduce risk but do not eliminate it. Patching remains the only complete remediation.

AJA Remediation Status

HELO Plus - Fixed

HELO Plus firmware v2.1.6, released August 4, 2026, incorporates the fixed SRT library (v1.5.6 or later) and resolves both CVEs. All HELO Plus units running firmware prior to v2.1.6 are affected, and AJA strongly recommends updating immediately.

Firmware v2.1.6 and its release notes are available on the HELO Plus v2.1.6 download page, or from the Support tab of the HELO Plus product page.

BRIDGE LIVE - Patch in Development

AJA is actively developing a patch for BRIDGE LIVE (including BRIDGE LIVE 12G-4, BRIDGE LIVE 3G-8, and BRIDGE LIVE IP) to incorporate the fixed SRT library. This advisory will be updated with:

  • Target release dates for patched software
  • Upgrade instructions
  • Confirmation of testing/validation

BRIDGE LIVE customers are strongly encouraged to apply the immediate mitigations above while the patch is finalized.

References

Revision History

Date Change
August 4, 2026 HELO Plus firmware v2.1.6 released, resolving both CVEs. BRIDGE LIVE patch still in development.
July 24, 2026 Initial publication.

Contact

For questions regarding this advisory or assistance with mitigation, contact security@aja.com.

This advisory will be updated as new information becomes available.