MEDIUM
versatica
CVE published 2026-08-25
CVE-2026-55663
A vulnerability in mediasoup, a WebRTC video conferencing system, allows an on-path attacker to forge a COOKIE-ECHO packet and establish an unauthorized SCTP association, permitting DataChannel message injection as a trusted peer. This issue affects versions 3.20.0 through 3.20.6 of the npm package and versions 0.22.0 through 0.22.5 of the Rust crate. The vulnerability is due to the use of hardcoded magic [truncated]