CVE-2026-55663Medium· 5.6▾ Sunlitmediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded m…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 26.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
mediasoup >= 3.20.0, <= 3.20.5mediasoup >= 0.22.0, <= 0.22.4Patched in:
mediasoup 3.20.6mediasoup 0.22.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86038High· 7.5libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2026-73846Medium· 6.5CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2026-53728High· 7.1Medplum is a developer platform that enables development of healthcare apps
CVE-2026-68945HighAngular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
GHSA-pvcr-8mvp-w8qrHigh· 7.7Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)