PatchSiren

versatica CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM versatica CVE published 2026-08-25

CVE-2026-55663

A vulnerability in mediasoup, a WebRTC video conferencing system, allows an on-path attacker to forge a COOKIE-ECHO packet and establish an unauthorized SCTP association, permitting DataChannel message injection as a trusted peer. This issue affects versions 3.20.0 through 3.20.6 of the npm package and versions 0.22.0 through 0.22.5 of the Rust crate. The vulnerability is due to the use of hardcoded magic [truncated]