v1.18.1
Added 2
- Support reading and writing KLV in HLS
- Add hlsCDNSecret option to serve HLS streams behind a CDN in a simplified way
Changed 3
- Use temporary redirects instead of permanent redirects to prevent unwanted caching
- Add public attribute to cache-control header in HLS
- Allow caching non-low-latency HLS playlists
Fixed 1
- Merge request controls instead of overwriting in RPI Camera to support libcamera 0.7.0
Security 3
- Prevent code injection in case of MTX_QUERY in hooks by url-encoding MTX_QUERY
- Prevent open redirect attacks in HLS
- Prevent open redirect attacks in WebRTC
Fixes and improvements
General
- prevent code injection in case of MTX_QUERY in hooks (https://github.com/bluenviron/mediamtx/issues/5707) When MTX_QUERY is used explicitly in hooks, for instance "curl http://something/?$MTX_QUERY", it can be used to inject arbitrary commands. MTX_QUERY is now url-encoded to prevent any abuse regardless of the configuration.
- use temporary redirects instead of permanent redirects (https://github.com/bluenviron/mediamtx/issues/5710) this prevents unwanted caching.
HLS
- prevent open redirect attacks (https://github.com/bluenviron/mediamtx/issues/5708)
- support reading and writing KLV (https://github.com/bluenviron/mediamtx/issues/5604)
- add hlsCDNSecret (https://github.com/bluenviron/mediamtx/issues/5716) this allows to serve HLS streams behind a CDN in a simplified way, compatible with the new HLS session system.
- add public attribute to cache-control header (https://github.com/bluenviron/gohlslib/issues/349)
- allow caching non-low-latency playlists (https://github.com/bluenviron/gohlslib/issues/350)
WebRTC
- prevent open redirect attacks (https://github.com/bluenviron/mediamtx/issues/5708)
RPI Camera
- Merge request->controls instead of overwriting (https://github.com/bluenviron/mediamtx-rpicamera/issues/97) libcamera 0.7.0 is more strict about changing controls; assignment is no longer allowed since https://github.com/raspberrypi/libcamera/commit/310cd8bc0756717cde97fe5b083926f6d6931f58 Instead, we use the merge call with overwrite.
Security
Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.
Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
You can verify checksums of binaries by downloading checksums.sha256 and running:
cat checksums.sha256 | grep "$(ls mediamtx_*)" | sha256sum --check