Wowza Streaming Engine 4.12.0: Hardware transcoding, modern WebRTC and new stream targets

Hello everybody,

Wowza Streaming Engine (WSE) 4.12.0 is now available. The release adds hardware-accelerated transcoding options, new stream targets, and a reworked WebRTC stack, s well as bug and security fixes.

Please refer to the

complete 4.12.0 release notes

for a full list of changes, update and improvements, which are summarized below:

Version: Wowza Streaming Engine™ 4.12.0 build 20260929182413 released Sept 30, 2026.

Java support: Wowza Streaming Engine 4.12.0 is compiled using Java 17 (OpenJDK Java SE JRE 17.0.12). It can be used with Java versions 17 or 21. For more details, see Java version information.

Summary of new features and fixes

Hardware-accelerated transcoding

WSE now supports Intel QuickSync Video (H.264 and H.265 on Alder Lake and newer integrated GPUs) and NETINT Quadra VPUs on Linux x86-64. A new Hardware Presets dropdown in the transcoder template page in WSE Manager assigns IQSV, NETINT, or NVIDIA hardware acceleration to a whole template in one step.

New stream targets

  • Akamai MSL5: Set up targets with the new wizard in WSE Manager. Akamai MSL4 reaches end of life on December 31, 2026, so plan your migration.
  • WHIP: Push streams to external WHIP endpoints via WSE Manager or the REST API, including simulcast egress, RTX, ICE restart, and data channels.
  • Cloud storage: Configure targets directly in WSE Manager, including ABR with multiple streams.

A modernized WebRTC stack

  • Simulcast with per-viewer rendition selection, driven by TWCC bandwidth estimation (REMB as fallback)
  • NACK/RTX for packet-loss recovery, plus improved PLI handling
  • ICE restart for client-mode connections and a manual ICE mode
  • SCTP data channels for text and binary messages next to the media
  • Lower latency: roughly 66 ms less H.264 ingest latency at 30 fps, and faster time to first frame when many viewers connect at once
  • Reworked WebRTC settings per application in WSE Manager (General, ICE/Network, Simulcast, Advanced/RTP Feedback) and new connection statistics on the monitoring pages

Other improvements

  • HLS playlists now include the FRAME-RATE attribute by default.
  • Improved 10-bit SDR/HDR input handling for H.264 High10 and HEVC Main10.
  • New caption properties for DVB Teletext and WebVTT.
  • A per-stream RTSP option fixes pull sources from NAT’d cameras.

Bug fixes

  • Fixed green screen playback on standard definition (SD) sources when encoding, decoding, and scaling on GPU.
  • Fixed output aspect ratio mismatch on interlaced streams with a non-square sample aspect ratio (SAR).
  • Fixed bitrate drops, video stoppages, and frame skipping when using NVENC transcoding with a live 4K source.
  • Fixed roughly 300 ms of added latency when transcoding on NVIDIA GPUs.
  • Fixed various scaling and cropping issues.
  • Fixed a bug causing WSE to crash when transcoding an MPEG-2 source.
  • Fixed the native H.264 decoder segfaulting the JVM after rejecting a stream’s codec configuration. A rejected codec configuration now fails the stream instead of the server.
  • Fixed an undecoded character in subtitles from Teletext live stream sources.
  • Fixed a bug causing WebVTT captions to be duplicated during live playback.
  • Fixed a null pointer exception in the HLS live stream packetizer that interrupted captions. Caption chunks are now handled safely across a stream reset.
  • Fixed CEA-608/CEA-708 caption tracks missing from HLS push publish master manifests. Caption channels are now declared as EXT-X-MEDIA:TYPE=CLOSED-CAPTIONS entries and referenced from each variant stream. They can be configured with cupertino.closed-captions.* in PushPublishMap.txt or a SMIL <textstream>.
  • Fixed a bug in the CMAF packager causing fatal playback failures in Chrome and other MSE-based players when packaging HEVC/H.265 sources, such as streams published from an Ateme Titan encoder.
  • Fixed malformed playback URLs in HLS manifests written to Google Cloud Storage stream targets. A missing / separator between path segments prevented players from resolving the URLs.
  • Fixed a bug causing WSE to create and start a new app when a SMIL file referenced an existing app name with different capitalization.
  • Fixed a memory leak caused by overlay sessions not being released when destroying the video frame buffer.
  • MPEG-TS ingest: Fixed RTPMediaCaster refusing new MPEG-TS over UDP streams after an uncaught error, eventually causing an out-of-memory (OOM) crash. The worker now survives unexpected errors.
  • HLS and MPEG-DASH: Fixed HLS playlist, subtitle playlist, and WebVTT caption responses sharing the same strong ETag between gzip-compressed and uncompressed responses. Compressible HLS and MPEG-DASH playlist responses now include a Vary: Accept-Encoding header.
  • WebRTC signaling: Fixed WebSocket signaling sessions staying open after a peer connection teardown, leaving clients with a live signaling channel and dead media. WSE now closes the signaling session on every server-side teardown path.
  • Fixed a bug causing SecureToken validation to be ignored in WebRTC publish and playback sessions. Sessions with a missing, invalid, or expired token are now rejected.
  • Fixed a bug causing WebRTC sessions using SecureToken with securitySecureTokenIncludeClientIPInHash enabled to bind the IP to 127.0.0.1 instead of the connecting client IP.
  • Fixed a thread leak on WebRTC session teardown when TURN relay candidates were configured. Reader threads are now always stopped when the session’s socket closes.
  • Corrected the help text for the default WebRTC UDP port range to 6970-9999. (Note: This port range overlaps the RTP datagram range, so admins using both should select distinct ranges.)
  • WHIP and WHEP: Fixed failure responses omitting the Access-Control-Allow-Origin header, which caused cross-origin browser clients to report a CORS error instead of the actual failure status.
  • Updated the commented-out port 443 example in conf/VHost.xml. Uncommenting it now produces an SSL HostPort where WebRTC signaling works, with no further manual edits.
  • WebRTC playback is now counted in the outgoing byte totals on an incoming stream’s details page in WSE Manager.
  • Added the Server Boolean properties h264IgnoreSpsErrors and h264IgnorePpsErrors to skip strict H.264 SPS/PPS bit-length validation.
  • Fixed a WebRTC session being closed as idle while it was recovering from a UDP outage. The session now restarts ICE and continues over ICE-TCP.
  • Fixed the WebRTC loss-based estimator pinning the estimate at a suppressed rate.
  • Eliminated spurious warnings during successful DTLS secure renegotiation in WebRTC sessions.
  • Fixed WebSocket frame parsing dropping frames that arrived split across multiple TCP segments.

Security

  • Updated Jetty to version 12.1.11 to resolve CVE-2026-10050.
  • Updated log4j to version 2.25.5 to resolve CVE-2026-49844.
  • Updated Apache Tomcat to version 10.1.59 to resolve CVE-2026-65182, CVE-2026-65905, and CVE-2026-68525.
  • Updated snmp4j to version 3.13.1 and snmp4j-agent to version 3.10.1 to resolve CVE-2026-39006.
  • Added support for encrypted admin passwords in the WSE Docker container. Users can now supply an already-encrypted password, or have the container encrypt a cleartext password before it’s written to admin.password.

Upgrade notes

  • WSE 4.12.0 is built with Java 17 and runs on Java 17 or 21.
  • The default for MinTimeToLive in MediaCache.xml is now 3 seconds. Set your previous value explicitly if you want to keep it.
  • The default WebRTC UDP port range (6970-9999) overlaps with the RTP datagram range. Use distinct ranges if you use both.

Known issues


For a detailed list of currently known issues, see Known issues with Wowza Streaming Engine.

Bernd Backhaus
Technical Support Engineer
WOWZA | The solution you start with, the partner you scale with.

Manage your Support cases online
Bookmark our FAQ page
Bookmark our Status page

182x66.9749984741211

1 Like