{"id":"CVE-2026-55663","aliases":["GHSA-p7x2-g5cq-fhmq"],"url":"https://o3.security/vulnerability/CVE-2026-55663","summary":"mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)","details":"mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.","published":"2026-08-25T18:15:16.059Z","modified":"2026-08-27T19:14:09.385792Z","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"crates.io","name":"mediasoup","fixedVersion":"0.22.5"},{"ecosystem":"npm","name":"mediasoup","fixedVersion":"3.20.6"}],"fix":{"url":"https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7","label":"versatica/mediasoup@9c1a90a"},"references":[{"type":"WEB","url":"https://github.com/versatica/mediasoup/releases/tag/3.20.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55663.json"},{"type":"ADVISORY","url":"https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55663"},{"type":"FIX","url":"https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7"},{"type":"FIX","url":"https://github.com/versatica/mediasoup/pull/1829"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T19:14:09.385792Z"}}