SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-54632

HIGH · CVSS 7.5 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the SIPSorcery library for C# and .NET, specifically in the handling of RTP packets and STUN address attributes, which lack proper length checks. An attacker can exploit this flaw by sending a malformed STUN packet to disrupt active RTP or WebRTC media sessions, leading to denial of service without requiring authentication or user interaction. Organizations using versions prior to 10.0.9 should prioritize updating to mitigate potential service interruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54632
Severity
HIGH
CVSS
7.5
EPSS
0.54%

Original NVD Description

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can send a single short RTP packet or malformed zero-to-seven-byte STUN address attribute to the shared RTP/ICE socket, including during ICE connectivity checks before DTLS or STUN MESSAGE-INTEGRITY verification, and terminate the active RTP or WebRTC media session. The attacker must reach or learn the advertised ephemeral RTP/ICE port, but no authentication or user interaction is required, and the impact is limited to availability. This issue is fixed in version 10.0.9.