Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-28gm-jrmw-xx93 | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can send a single short RTP packet or malformed zero-to-seven-byte STUN address attribute to the shared RTP/ICE socket, including during ICE connectivity checks before DTLS or STUN MESSAGE-INTEGRITY verification, and terminate the active RTP or WebRTC media session. The attacker must reach or learn the advertised ephemeral RTP/ICE port, but no authentication or user interaction is required, and the impact is limited to availability. This issue is fixed in version 10.0.9. | |
| Title | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) | |
| Weaknesses | CWE-20 CWE-755 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T14:43:28.069Z
Reserved: 2026-06-15T20:07:02.185Z
Link: CVE-2026-54632
Updated: 2026-09-15T14:43:24.887Z
Status : Received
Published: 2026-09-14T20:16:47.010
Modified: 2026-09-15T15:17:18.310
Link: CVE-2026-54632
No data.
OpenCVE Enrichment
Updated: 2026-09-15T12:00:16Z
Github GHSA