THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p7x2-g5cq-fhmq (medium) — mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

[GHSA] GHSA-p7x2-g5cq-fhmq (medium) — mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

medgithub_advisoriesPublished 2026-08-25

GHSA-p7x2-g5cq-fhmq Severity: medium CVE: CVE-2026-55663

mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

### Summary

mediasoup's built-in SCTP stack (introduced in v3.20.0) authenticates SCTP state cookies using only hardcoded magic byte sequences rather than a per-instance HMAC keyed with a secret, violating

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p7x2-g5cq-fhmq