CVE-2026-54909

NameCVE-2026-54909
Descriptionpion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. This issue is fixed in version 3.1.3.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-github-pion-stun (PTS)bookworm0.4.0-1vulnerable
forky, trixie0.6.1-1vulnerable
sid0.6.1-2vulnerable
golang-github-pion-stun-v3 (PTS)forky3.0.2-1vulnerable
sid3.0.2-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-pion-stunsource(unstable)(unfixed)
golang-github-pion-stun-v3source(unstable)(unfixed)

Notes

https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc
https://github.com/pion/stun/pull/278
Fixed by: https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 (v3.1.3)

Search for package or bug name: Reporting problems