---
id: CVE-2026-55663
title: mediasoup is a WebRTC video conferencing system
summary: >-
  mediasoup is a WebRTC video conferencing system. From version 3.20.0 until
  3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate,
  mediasoup's built-in SCTP stack authenticates state cookies using only the
  hardcoded m…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-345
vendor: mediasoup
product: mediasoup
affected:
  - 'mediasoup >= 3.20.0, <= 3.20.5'
  - 'mediasoup >= 0.22.0, <= 0.22.4'
patched:
  - mediasoup 3.20.6
  - mediasoup 0.22.5
published: '2026-08-25'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:07:31.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55663'
references:
  - url: >-
      https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7
    label: security-advisories@github.com
  - url: 'https://github.com/versatica/mediasoup/pull/1829'
    label: security-advisories@github.com
  - url: 'https://github.com/versatica/mediasoup/releases/tag/3.20.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq
    label: security-advisories@github.com
  - url: >-
      https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/advisories/GHSA-p7x2-g5cq-fhmq'
tags:
  - nvd
  - ghsa
  - npm
epss: 0.00153
epssPercentile: 0.04861
aliases:
  - GHSA-p7x2-g5cq-fhmq
ecosystem: npm
ingestedAt: '2026-08-25T18:30:21.155Z'
---

## Overview

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55663)

Affected packages:

- `mediasoup >= 3.20.0, <= 3.20.5`
- `mediasoup >= 0.22.0, <= 0.22.4`

Patched in:

- `mediasoup 3.20.6`
- `mediasoup 0.22.5`

Source: https://github.com/advisories/GHSA-p7x2-g5cq-fhmq
