{"apiVersion":"1.0","identifier":"CVE-2026-55663","description":"mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup-s built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.","publishedAt":"2026-08-25T19:16:51","lastModifiedAt":"2026-08-25T19:16:51","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55663","cvssScore":5.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","epssProbability":0.00153,"riskScore":0.57,"affectedProduct":"mediasoup","affectedVersions":">=3.20.0,<3.20.6","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-55663","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-55663","en":"https://www.redsauce.net/en/cves/CVE-2026-55663","fr":"https://www.redsauce.net/fr/cves/CVE-2026-55663","pt":"https://www.redsauce.net/pt/cves/CVE-2026-55663","de":"https://www.redsauce.net/de/cves/CVE-2026-55663","sk":"https://www.redsauce.net/sk/cves/CVE-2026-55663","el":"https://www.redsauce.net/el/cves/CVE-2026-55663"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-55663"}}