MEDIUMGo

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

CVE-2026-54909Published 5 days agoUpdated 4 days agoSource: OSV

Affected packages

  • github.com/pion/stun
  • github.com/pion/stun/v2
  • github.com/pion/stun/v3

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.37%
EPSS percentile
29.8%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 30%.

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute | HackTribune