v1.18.2

arhamkhnz/next-shadcn-admin-dashboardv1.18.2May 15, 2026by github-actions[bot]

AI Summary

This patch release focuses on fixing stability and compatibility issues across multiple streaming protocols (RTSP, RTMP, HLS, WebRTC) and introduces security measures for binary verification.

Key Highlights

  • RTSP compatibility fixes for Verint.Vms.MediaGateway
  • HLS error 500 fix for in-stream parameters
  • WebRTC support for trickle ICE and WHICE restarts
  • Security verification of binaries via GitHub Attestations

New Features

  • RTSP compatibility and crash fixes
  • RTMP nil/unconfigured track prevention
  • HLS error 500 fix
  • WebRTC trickle ICE and restart support
  • RPI Camera dynamic text overlay
  • Security binary verification

Full Release Notes

## Fixes and improvements

RTSP

* fix compatibility with Verint.Vms.MediaGateway (https://github.com/bluenviron/mediamtx/issues/5292) (https://github.com/bluenviron/gortsplib/issues/1061)
* fix crash when stream is closing (https://github.com/bluenviron/gortsplib/issues/1062) when ServerStream.Close() is called, stream readers might have their setuppedTransport set to nil, causing the server to crash. Prevent this.
* fix race condition when tearing down connection (https://github.com/bluenviron/gortsplib/issues/1063) ServerConn.session was not properly protected.
* fix leak in case of failure during multicast initialization (https://github.com/bluenviron/gortsplib/issues/1064)

RTMP

* prevent nil / unconfigured tracks from appearing (https://github.com/bluenviron/gortmplib/issues/66) (https://github.com/bluenviron/mediamtx/issues/5724) (https://github.com/bluenviron/mediamtx/issues/5729)

HLS

* fix error 500 caused by in-stream params (https://github.com/bluenviron/gohlslib/issues/355) (https://github.com/bluenviron/mediamtx/issues/5728) (https://github.com/bluenviron/mediamtx/issues/5745) PR https://github.com/bluenviron/gohlslib/issues/344 caused a regression. Many codecs (AV1, H264, H265, VP9) use in-stream parameters, that were not taken into consideration anymore when generating init.mp4 and playlists. This has been solved.

WebRTC

* fix checking POST responses (https://github.com/bluenviron/mediamtx/issues/5758)
* support interacting with servers with no trickle ICE (https://github.com/bluenviron/mediamtx/issues/5273) (https://github.com/bluenviron/mediamtx/issues/5757)
* support WHIP ICE restarts (https://github.com/bluenviron/mediamtx/issues/5183) (https://github.com/bluenviron/mediamtx/issues/5770)

RPI Camera

* support changing text overlay dynamically (https://github.com/bluenviron/mediamtx/issues/5270) (https://github.com/bluenviron/mediamtx/issues/5748)

Dependencies

* code.cloudfoundry.org/bytefmt updated from v0.70.0 to v0.72.0
* github.com/Masterminds/semver/v3 updated from v3.4.0 to v3.5.0
* github.com/bluenviron/gohlslib/v2 updated from v2.3.1 to v2.3.2
* github.com/bluenviron/gortmplib updated from v0.3.1 to v0.3.2
* github.com/bluenviron/gortsplib/v5 updated from v5.5.2 to v5.5.3
* github.com/datarhei/gosrt updated from v0.10.0 to v0.11.0
* github.com/fsnotify/fsnotify updated from v1.10.0 to v1.10.1
* github.com/go-git/go-billy/v5 updated from v5.8.0 to v5.9.0
* github.com/go-git/go-git/v5 updated from v5.18.0 to v5.19.0
* github.com/gookit/color updated from v1.6.0 to v1.6.1
* github.com/matthewhartstonge/argon2 updated from v1.5.2 to v1.5.3
* github.com/pion/rtp updated from v1.10.1 to v1.10.2
* golang.org/x/crypto updated from v0.50.0 to v0.51.0
* golang.org/x/net updated from v0.53.0 to v0.54.0
* golang.org/x/sys updated from v0.43.0 to v0.44.0
* golang.org/x/term updated from v0.42.0 to v0.43.0
* github.com/cyphar/filepath-securejoin updated from v0.4.1 to v0.6.1
* github.com/pjbgf/sha1cd updated from v0.3.2 to v0.6.0
* golang.org/x/text updated from v0.36.0 to v0.37.0
* github.com/bluenviron/mediamtx-rpicamera updated from v2.5.6 to v2.5.7

## Security

Binaries are compiled from source code by the [Release workflow](https://github.com/bluenviron/mediamtx/actions/workflows/release.yml), which is a fully-visible process that prevents any change or external interference in produced artifacts.

Checksums of binaries are also published in a public blockchain by using [GitHub Attestations](https://docs.github.com/en/actions/concepts/security/artifact-attestations), and they can be verified by running:

```
ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx
```

You can verify checksums of binaries by downloading `checksums.sha256` and running:

```
cat checksums.sha256 | grep "$(ls mediamtx_*)" | sha256sum --check
```