CVE-2026-55663 (GCVE-0-2026-55663)
Vulnerability from cvelistv5
Published
2026-08-25 18:15
Modified
2026-08-25 18:55
CWE
  • CWE-345 - Insufficient Verification of Data Authenticity
Summary
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.
Impacted products
Vendor Product Version
versatica mediasoup Version: >= 3.20.0, < 3.20.6
Version: >= 0.22.0, < 0.22.5
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-55663",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-25T18:55:43.763697Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-25T18:55:59.044Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "mediasoup",
          "vendor": "versatica",
          "versions": [
            {
              "status": "affected",
              "version": "\u003e= 3.20.0, \u003c 3.20.6"
            },
            {
              "status": "affected",
              "version": "\u003e= 0.22.0, \u003c 0.22.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup\u0027s built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-345",
              "description": "CWE-345: Insufficient Verification of Data Authenticity",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-25T18:15:16.059Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq"
        },
        {
          "name": "https://github.com/versatica/mediasoup/pull/1829",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/versatica/mediasoup/pull/1829"
        },
        {
          "name": "https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7"
        },
        {
          "name": "https://github.com/versatica/mediasoup/releases/tag/3.20.6",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/versatica/mediasoup/releases/tag/3.20.6"
        }
      ],
      "source": {
        "advisory": "GHSA-p7x2-g5cq-fhmq",
        "discovery": "UNKNOWN"
      },
      "title": "mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-55663",
    "datePublished": "2026-08-25T18:15:16.059Z",
    "dateReserved": "2026-06-17T00:05:03.777Z",
    "dateUpdated": "2026-08-25T18:55:59.044Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-55663\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"poc\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-25T18:55:43.763697Z\"}}}], \"references\": [{\"url\": \"https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq\", \"tags\": [\"exploit\"]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-25T18:55:52.575Z\"}}], \"cna\": {\"title\": \"mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)\", \"source\": {\"advisory\": \"GHSA-p7x2-g5cq-fhmq\", \"discovery\": \"UNKNOWN\"}, \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.6, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L\", \"integrityImpact\": \"LOW\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"HIGH\", \"availabilityImpact\": \"LOW\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"LOW\"}}], \"affected\": [{\"vendor\": \"versatica\", \"product\": \"mediasoup\", \"versions\": [{\"status\": \"affected\", \"version\": \"\u003e= 3.20.0, \u003c 3.20.6\"}, {\"status\": \"affected\", \"version\": \"\u003e= 0.22.0, \u003c 0.22.5\"}]}], \"references\": [{\"url\": \"https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq\", \"name\": \"https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq\", \"tags\": [\"x_refsource_CONFIRM\"]}, {\"url\": \"https://github.com/versatica/mediasoup/pull/1829\", \"name\": \"https://github.com/versatica/mediasoup/pull/1829\", \"tags\": [\"x_refsource_MISC\"]}, {\"url\": \"https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7\", \"name\": \"https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7\", \"tags\": [\"x_refsource_MISC\"]}, {\"url\": \"https://github.com/versatica/mediasoup/releases/tag/3.20.6\", \"name\": \"https://github.com/versatica/mediasoup/releases/tag/3.20.6\", \"tags\": [\"x_refsource_MISC\"]}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup\u0027s built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-345\", \"description\": \"CWE-345: Insufficient Verification of Data Authenticity\"}]}], \"providerMetadata\": {\"orgId\": \"a0819718-46f1-4df5-94e2-005712e83aaa\", \"shortName\": \"GitHub_M\", \"dateUpdated\": \"2026-08-25T18:15:16.059Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-55663\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-25T18:55:59.044Z\", \"dateReserved\": \"2026-06-17T00:05:03.777Z\", \"assignerOrgId\": \"a0819718-46f1-4df5-94e2-005712e83aaa\", \"datePublished\": \"2026-08-25T18:15:16.059Z\", \"assignerShortName\": \"GitHub_M\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…