{"id":"CVE-2026-55663","title":"mediasoup is a WebRTC video conferencing system","summary":"mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded m…","severity":"medium","cvss":5.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-345"],"vendor":"mediasoup","product":"mediasoup","affected":["mediasoup >= 3.20.0, <= 3.20.5","mediasoup >= 0.22.0, <= 0.22.4"],"patched":["mediasoup 3.20.6","mediasoup 0.22.5"],"published":"2026-08-25","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:07:31.353","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55663","references":[{"url":"https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7","label":"security-advisories@github.com"},{"url":"https://github.com/versatica/mediasoup/pull/1829","label":"security-advisories@github.com"},{"url":"https://github.com/versatica/mediasoup/releases/tag/3.20.6","label":"security-advisories@github.com"},{"url":"https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq","label":"security-advisories@github.com"},{"url":"https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-p7x2-g5cq-fhmq"}],"tags":["nvd","ghsa","npm"],"epss":0.00153,"epssPercentile":0.04861,"aliases":["GHSA-p7x2-g5cq-fhmq"],"ecosystem":"npm","ingestedAt":"2026-08-25T18:30:21.155Z","slug":"CVE-2026-55663","body":"## Overview\n\nmediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55663)\n\nAffected packages:\n\n- `mediasoup >= 3.20.0, <= 3.20.5`\n- `mediasoup >= 0.22.0, <= 0.22.4`\n\nPatched in:\n\n- `mediasoup 3.20.6`\n- `mediasoup 0.22.5`\n\nSource: https://github.com/advisories/GHSA-p7x2-g5cq-fhmq","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}