Remote Denial of Service Vulnerability in Pion STUN Client by Pion
CVE-2026-54909
5.3MEDIUM
What is CVE-2026-54909?
The Pion STUN client, a Go-based implementation of the STUN protocol, has a vulnerability that allows for remote denial of service. When processing a malformed short XOR-MAPPED-ADDRESS attribute during the ICE Binding-response phase, the XORMappedAddress.GetFromAs function can panic, leading to potential service interruptions. This issue has been addressed in version 3.1.3, ensuring that such parsing vulnerabilities are mitigated.
Affected Version(s)
stun < 3.1.3
