CVE-2026-100251
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wormhole App | Wormhole | 0 < 2026-08-22 | affected |
| Wormhole App | Wormhole | 2026-08-22 | unaffected |
Weaknesses
- CWE-918: CWE-918 Server-Side Request Forgery (SSRF)
References
- https://wormhole.app/
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-275-04.json
- https://www.cve.org/CVERecord?id=CVE-2026-100251
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.