VYPR
Medium severity5.3NVD Advisory· Published Jul 31, 2026· Updated Sep 10, 2026

CVE-2026-54909

CVE-2026-54909

Description

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. This issue is fixed in version 3.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/pion/stun/v3Go
< 3.1.53.1.5
github.com/pion/stun/v2Go
<= 2.0.0
github.com/pion/stunGo
<= 1.23.1

Affected products

43

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.