ex_webrtc
Implementation of the W3C WebRTC API
Activity
- Latest release
- 2mo ago
- Total releases
- 25
- Cadence
- ~24 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Feb 07, 2024
| Version | Released | |
|---|---|---|
0.17.0
minor
| ||
0.15.1
patch
| ||
0.16.1
patch
| ||
0.16.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.15.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.8.1
patch
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.6.3
patch
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.6.2
patch
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2026-44700
GHSA-qwfw-ggxw-577c
May 08, 2026
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
High
Network
Low
None
None
SummaryMissing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. Details
All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1. ImpactThe bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check. On its own, the bug does not allow:
The bug does enable a full MITM on media and data channels when combined with any of:
Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected. Patches
WorkaroundsNone. Upgrade is required. ResourcesAffected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
+ 10 more Show less
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.16.0
Fixed in
0.15.1
0.16.1
References
Updated May 16, 2026 · Source: OSV.dev |