{"id":"CVE-2021-28681","aliases":["GHSA-74xm-qj29-cq8p","GO-2021-0104"],"url":"https://o3.security/vulnerability/CVE-2021-28681","summary":"In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication","details":"Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to continue if verification has failed.)","published":"2021-03-18T04:15:14.617Z","modified":"2026-07-09T11:23:57.013147Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/pion/webrtc/v3","fixedVersion":"3.0.15"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/pion/webrtc/security/advisories/GHSA-74xm-qj29-cq8p"},{"type":"FIX","url":"https://github.com/pion/webrtc/issues/1708"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:23:57.013147Z"}}