---
id: CVE-2026-100251
title: >-
  Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN
  server and does not properly restrict TCP relay peers, allowing an
  unauthenticated attacker to access instance metadata or to source TCP
  connections from the Wormho…
summary: >-
  Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN
  server and does not properly restrict TCP relay peers, allowing an
  unauthenticated attacker to access instance metadata or to source TCP
  connections from the Wormho…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: Wormhole App
product: Wormhole
affected:
  - Wormhole < 2026-08-22
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:37:52.400'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100251'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-275-04.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://wormhole.app/'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-100251'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T19:58:57.560Z'
---

## Overview

Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
