Medium severity6.5NVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-100251
CVE-2026-100251
Description
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2026-08-22
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.