๐Ÿ” CVE Alert

CVE-2026-100251

MEDIUM 6.5

Wormhole.app SSRF

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.

CWE CWE-918
Vendor wormhole app
Product wormhole
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for wormhole app wormhole

Be the first to know when new medium vulnerabilities affecting wormhole app wormhole are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Wormhole App / Wormhole
0 < 2026-08-22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wormhole.app: https://wormhole.app/ raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-275-04.json cve.org: https://www.cve.org/CVERecord?id=CVE-2026-100251

Credits

Shreyash Naik