Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-28gm-jrmw-xx93 | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can send a single short RTP packet or malformed zero-to-seven-byte STUN address attribute to the shared RTP/ICE socket, including during ICE connectivity checks before DTLS or STUN MESSAGE-INTEGRITY verification, and terminate the active RTP or WebRTC media session. The attacker must reach or learn the advertised ephemeral RTP/ICE port, but no authentication or user interaction is required, and the impact is limited to availability. This issue is fixed in version 10.0.9. | |
| Title | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) | |
| Weaknesses | CWE-20 CWE-755 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T19:58:30.394Z
Reserved: 2026-06-15T20:07:02.185Z
Link: CVE-2026-54632
No data.
Status : Received
Published: 2026-09-14T20:16:47.010
Modified: 2026-09-14T20:16:47.010
Link: CVE-2026-54632
No data.
OpenCVE Enrichment
No data.
Github GHSA