Version: Wowza Streaming Engine™ 4.12.0 build 20260929182413 released Sept 30, 2026.
Java support: Wowza Streaming Engine 4.12.0 is compiled using Java 17 (OpenJDK Java SE JRE 17.0.12). It can be used with Java versions 17 or 21. For more details, see Java version information.
Overview
The Wowza Streaming Engine (WSE) 4.12.0 release adds additional support for hardware-accelerated transcoding with Intel QuickSync Video (IQSV) and NETINT, support for Akamai MSL5 and WHIP stream targets, and the option to configure cloud storage stream targets using WSE Manager. It also modernizes its WebRTC stack with simulcast, transport-wide congestion control (TWCC) bandwidth estimation, NACK/RTX, improved Picture Loss Indication (PLI) handling, ICE restart, and data channels.
This release also brings several updates to WSE Manager. WebRTC settings for each application have been rebuilt and are now organized into General, ICE/Network, Simulcast, and Advanced/RTP Feedback tabs, and WebRTC connection statistics are now available on the Application Monitoring and Server Monitoring pages. The transcoder template page adds a Hardware Presets dropdown, and new stream targets are available for Akamai MSL5, WHIP, and cloud storage.
Detailed list of changes
Improvements
Hardware-accelerated transcoding
- Added support for Intel QuickSync Video (IQSV) hardware-accelerated transcoding. IQSV supports H.264 and H.265 transcoding on Alder Lake and newer Intel integrated GPUs. It also includes the following:
- Runtime adapter detection and graceful fallback to software processing.
- UI items in WSE Manager previously labeled 'QuickSync' are now labeled 'Legacy QuickSync'. Both paths remain functional.
- Added support for NETINT hardware-accelerated transcoding. NETINT supports H.264 and H.265 transcoding on Linux x86-64 machines with NETINT Quadra VPUs.
- Added a Hardware Presets dropdown to the transcoder template page in WSE Manager. Users can now assign IQSV, NETINT, or NVIDIA EVA across a transcoder template with a single action.
Stream targets
- Akamai MSL5: Added support for Akamai MSL5 stream targets. Admins can create an MSL5 stream target in WSE Manager using the Akamai MSL5 wizard. (The Akamai MSL4 wizard is still available and is labeled 'Akamai MSL4'.) Akamai MSL4 reaches end of life on December 31, 2026. Customers using Akamai MSL4 should move to MSL5 as soon as possible.
- Cloud storage stream targets: Users can now configure cloud storage stream targets directly in WSE Manager. For ABR, many different streams are now supported through the UI.
- WHIP-based stream targets: Added support for WHIP-based stream targets. Users can now push a stream to an external WHIP endpoint using WSE Manager or the REST API. This includes support for simulcast egress, outgoing RTX, ICE restart, and data channels.
Captions
- Added a DVBTeletext caption property,
mpegtsDVBTeletextRespectRowLineBreaks, that separates each Teletext row with line breaks in the caption text based on the parsed row boundary. - Added a WebVTT caption property,
webVTTCaptionConverterEscapeCharacters, that sets which characters are escaped in WebVTT cue text.
WebRTC improvements
- Simulcast and bandwidth estimation:
- WebRTC now supports simulcast with per-viewer rendition selection. Publishers can send multiple quality layers, and viewers receive the layer that matches their bandwidth estimate.
- Simulcast works with the new transport-wide congestion control (TWCC) bandwidth estimator. (When TWCC isn't supported, REMB is used as the fallback bandwidth estimator.)
- The WebRTC example pages now include a simulcast configuration section on the Publish tab.
- NACK/RTX: WSE now supports negative acknowledgement (NACK) and retransmission (RTX) on WebRTC streams. Receivers can now request lost packets, and WSE retransmits them on a dedicated RTX stream. NACK and RTX can each be enabled or disabled using WSE Manager or the WSE REST API.
- Picture Loss Indication (PLI): Improved PLI support, including SDP negotiation and inbound PLI handling. WSE now requests a fresh keyframe from the publisher when a decoder loses sync.
- Interactive Connectivity Establishment (ICE):
- Added ICE restart support for WebRTC client-mode connections, including WHIP stream targets. A connection now renegotiates connectivity and resumes on a new candidate pair when the network path changes, so publishing recovers without a full reconnect.
- Added a per-application manual ICE mode that allows server admins to disable automatic candidate harvesting.
- Data channels:
- Applications can now exchange text and binary messages over SCTP on the same peer connection that carries media. This enables use cases such as in-band metadata, control and signaling messages, and timed events alongside the media streams.
- The WebRTC example pages now demonstrate opening a data channel, sending and receiving string and binary messages, and channel state.
- WSE Manager improvements:
- WebRTC connection statistics can now be viewed on the Application Monitoring and Server Monitoring pages of WSE Manager.
- ICE candidates can now be viewed on the ICE/Network tab of a WebRTC app's settings page.
- Rebuilt the WebRTC per-application section in WSE Manager, with per-app enable/disable and settings split into General, ICE/Network, Simulcast, and Advanced/RTP Feedback tabs.
- The debug log can now be enabled in WSE Manager or the WSE REST API.
- Added a data channels toggle that allows server admins to enable data channels in WSE Manager.
- General WebRTC improvements:
- Added the ability to confine UDP ports to a user-defined port range.
- Bounded outbound buffering on WebRTC data channels to prevent a slow or stalled peer from driving unbounded memory growth on the server.
- Reduced per-connection thread usage on the WebRTC data channel send path. Send threads no longer scale one-for-one with the number of concurrent data channel connections.
- Reduced WebRTC H.264 ingest latency by roughly two frame intervals, about 66 ms at 30 fps.
- Improved time to first frame when many viewers connect at once. Players no longer fall into multi-second connection delays or hit their connect timeout while waiting for the DTLS handshake to complete.
General improvements
- HLS playlists now emit the
FRAME-RATEattribute by default. To disable the frame rate attribute, setcupertinoCalculateFrameRatetofalsein the HLS/Cupertino HTTP streamer's<Properties>block of the app'sApplication.xmlconfiguration file. - Enhanced 10-bit SDR and HDR input support in the live transcoder for H.264 High10 and HEVC Main10 sources.
- Added a per-stream RTSP property that forces RTSP SETUP and PLAY requests to the configured stream host. This fixes pull sources from NAT'd cameras that advertise a private IP address in their SDP.
- Updated the default for the MediaCache
MinTimeToLiveto 3 seconds. Note: This changes behavior on upgrade. To keep the previous value, setMinTimeToLiveinMediaCache.xml.
Bug fixes
- Fixed green screen playback on standard definition (SD) sources when encoding, decoding, and scaling on GPU.
- Fixed output aspect ratio mismatch on interlaced streams with a non-square sample aspect ratio (SAR).
- Fixed bitrate drops, video stoppages, and frame skipping when using NVENC transcoding with a live 4K source.
- Fixed roughly 300 ms of added latency when transcoding on NVIDIA GPUs.
- Fixed various scaling and cropping issues.
- Fixed a bug causing WSE to crash when transcoding an MPEG-2 source.
- Fixed the native H.264 decoder segfaulting the JVM after rejecting a stream's codec configuration. A rejected codec configuration now fails the stream instead of the server.
- Fixed an undecoded character in subtitles from Teletext live stream sources.
- Fixed a bug causing WebVTT captions to be duplicated during live playback.
- Fixed a null pointer exception in the HLS live stream packetizer that interrupted captions. Caption chunks are now handled safely across a stream reset.
- Fixed CEA-608/CEA-708 caption tracks missing from HLS push publish master manifests. Caption channels are now declared as
EXT-X-MEDIA:TYPE=CLOSED-CAPTIONSentries and referenced from each variant stream. They can be configured withcupertino.closed-captions.*inPushPublishMap.txtor a SMIL<textstream>. - Fixed a bug in the CMAF packager causing fatal playback failures in Chrome and other MSE-based players when packaging HEVC/H.265 sources, such as streams published from an Ateme Titan encoder.
- Fixed malformed playback URLs in HLS manifests written to Google Cloud Storage stream targets. A missing
/separator between path segments prevented players from resolving the URLs. - Fixed a bug causing WSE to create and start a new app when a SMIL file referenced an existing app name with different capitalization.
- Fixed a memory leak caused by overlay sessions not being released when destroying the video frame buffer.
- MPEG-TS ingest: Fixed
RTPMediaCasterrefusing new MPEG-TS over UDP streams after an uncaught error, eventually causing an out-of-memory (OOM) crash. The worker now survives unexpected errors. - HLS and MPEG-DASH: Fixed HLS playlist, subtitle playlist, and WebVTT caption responses sharing the same strong ETag between gzip-compressed and uncompressed responses. Compressible HLS and MPEG-DASH playlist responses now include a
Vary: Accept-Encodingheader. - WebRTC signaling: Fixed WebSocket signaling sessions staying open after a peer connection teardown, leaving clients with a live signaling channel and dead media. WSE now closes the signaling session on every server-side teardown path.
- Fixed a bug causing SecureToken validation to be ignored in WebRTC publish and playback sessions. Sessions with a missing, invalid, or expired token are now rejected.
- Fixed a bug causing WebRTC sessions using SecureToken with
securitySecureTokenIncludeClientIPInHashenabled to bind the IP to 127.0.0.1 instead of the connecting client IP. - Fixed a thread leak on WebRTC session teardown when TURN relay candidates were configured. Reader threads are now always stopped when the session's socket closes.
- Corrected the help text for the default WebRTC UDP port range to 6970-9999. (Note: This port range overlaps the RTP datagram range, so admins using both should select distinct ranges.)
- WHIP and WHEP: Fixed failure responses omitting the
Access-Control-Allow-Originheader, which caused cross-origin browser clients to report a CORS error instead of the actual failure status. - Updated the commented-out port 443 example in
conf/VHost.xml. Uncommenting it now produces an SSL HostPort where WebRTC signaling works, with no further manual edits. - WebRTC playback is now counted in the outgoing byte totals on an incoming stream's details page in WSE Manager.
- Added the Server Boolean properties
h264IgnoreSpsErrorsandh264IgnorePpsErrorsto skip strict H.264 SPS/PPS bit-length validation. This allows encoders with non-compliant but usable streams to publish successfully. - Fixed a WebRTC session being closed as idle while it was recovering from a UDP outage. The session now restarts ICE and continues over ICE-TCP.
- Fixed the WebRTC loss-based estimator pinning the estimate at a suppressed rate.
- Eliminated spurious warnings during successful DTLS secure renegotiation in WebRTC sessions.
- Fixed WebSocket frame parsing dropping frames that arrived split across multiple TCP segments. On WebRTC signaling connections, this caused WSE to stop sending validation pings after a Safari/iOS client sent a Pong frame in several segments, leaving the session open but silent until an idle timeout closed it.
Security
- Updated Jetty to version 12.1.11 to resolve CVE-2026-10050.
- Updated log4j to version 2.25.5 to resolve CVE-2026-49844.
- Updated Apache Tomcat to version 10.1.59 to resolve CVE-2026-65182, CVE-2026-65905, and CVE-2026-68525.
- Updated snmp4j to version 3.13.1 and snmp4j-agent to version 3.10.1 to resolve CVE-2026-39006.
- Added support for encrypted admin passwords in the WSE Docker container. Users can now supply an already-encrypted password, or have the container encrypt a cleartext password before it's written to
admin.password.
Known issues
For a detailed list of currently known issues, see Known issues with Wowza Streaming Engine.




