SCTP Association Vulnerability in mediasoup Video Conferencing System by Versatica
CVE-2026-55663
5.6MEDIUM
What is CVE-2026-55663?
A vulnerability exists in the mediasoup WebRTC video conferencing system where the built-in SCTP stack improperly authenticates state cookies using hardcoded values. This flaw allows an attacker to forge a COOKIE-ECHO message that could establish an unauthorized SCTP association. The attack could be executed against PlainTransport or PipeTransport when SCTP is enabled and without DTLS protection, enabling the attacker to inject DataChannel messages as if they were a trusted peer. This issue is resolved in npm version 3.20.6 and Rust crate version 0.22.5.
Affected Version(s)
mediasoup >= 3.20.0, < 3.20.6 < 3.20.0, 3.20.6
mediasoup >= 0.22.0, < 0.22.5 < 0.22.0, 0.22.5
