{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "3.20.0"
              },
              {
                "fixed": "3.20.6"
              },
              {
                "introduced": "0.22.0"
              },
              {
                "fixed": "0.22.5"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "2d14dd510f638c45f70f02c4105be81c0391c7cc"
            },
            {
              "fixed": "9c1a90a8f9206b965e727d134846fb42df4980a7"
            },
            {
              "fixed": "5b71d9fa1c126ade85957da3dc061dc0f7b5f929"
            }
          ],
          "repo": "https://github.com/versatica/mediasoup",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-p7x2-g5cq-fhmq"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-345"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55663.json"
  },
  "details": "mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.",
  "id": "CVE-2026-55663",
  "modified": "2026-08-27T11:30:57.795373494Z",
  "published": "2026-08-25T18:15:16.059Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/versatica/mediasoup/releases/tag/3.20.6"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55663.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/versatica/mediasoup/security/advisories/GHSA-p7x2-g5cq-fhmq"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55663"
    },
    {
      "type": "FIX",
      "url": "https://github.com/versatica/mediasoup/commit/9c1a90a8f9206b965e727d134846fb42df4980a7"
    },
    {
      "type": "FIX",
      "url": "https://github.com/versatica/mediasoup/pull/1829"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)"
}