SCTP Association Vulnerability in mediasoup Video Conferencing System by Versatica
CVE-2026-55663

5.6MEDIUM

Key Information:

Vendor

Versatica

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55663?

A vulnerability exists in the mediasoup WebRTC video conferencing system where the built-in SCTP stack improperly authenticates state cookies using hardcoded values. This flaw allows an attacker to forge a COOKIE-ECHO message that could establish an unauthorized SCTP association. The attack could be executed against PlainTransport or PipeTransport when SCTP is enabled and without DTLS protection, enabling the attacker to inject DataChannel messages as if they were a trusted peer. This issue is resolved in npm version 3.20.6 and Rust crate version 0.22.5.

Affected Version(s)

mediasoup >= 3.20.0, < 3.20.6 < 3.20.0, 3.20.6

mediasoup >= 0.22.0, < 0.22.5 < 0.22.0, 0.22.5

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.