๐Ÿ” CVE Alert

CVE-2026-55663

MEDIUM 5.6

mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

CVSS Score
5.6
EPSS Score
0.0%
EPSS Percentile
0th

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.

CWE CWE-345
Vendor versatica
Product mediasoup
Published Aug 25, 2026
Last Updated Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for versatica mediasoup

Be the first to know when new medium vulnerabilities affecting versatica mediasoup are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

versatica / mediasoup
>= 3.20.0, < 3.20.6 >= 0.22.0, < 0.22.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq github.com: https://github.com/versatica/mediasoup/pull/1829 github.com: https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7 github.com: https://github.com/versatica/mediasoup/releases/tag/3.20.6