DTLS Peer Certificate Vulnerability in Elixir WebRTC Implementation
CVE-2026-44700
8.7HIGH
What is CVE-2026-44700?
The Elixir WebRTC, an Elixir implementation of the W3C WebRTC API, contains a vulnerability in its DTLS client role that fails to validate peer certificate fingerprints. This flaw compromises the mutual authentication that WebRTC typically enforces, although it is not directly exploitable for media interception under standard configurations. Nonetheless, when combined with insecure signaling methods or other peers lacking proper validation, it creates a significant risk of man-in-the-middle attacks. This issue has been addressed in the versions 0.15.1 and 0.16.1.
Affected Version(s)
ex_webrtc < 0.15.1 < 0.15.1
ex_webrtc >= 0.16.0, < 0.16.1 < 0.16.0, 0.16.1
