GHSA-qwfw-ggxw-577c

Suggest an improvement
Source
https://github.com/advisories/GHSA-qwfw-ggxw-577c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qwfw-ggxw-577c/GHSA-qwfw-ggxw-577c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qwfw-ggxw-577c
Aliases
Published
2026-05-08T17:08:18Z
Modified
2026-05-16T00:10:10Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
Details

Summary

Missing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps.

Details

ex_webrtc validates the DTLS peer's certificate fingerprint against the value advertised in the SDP offer/answer when acting as the DTLS server (passive role). When acting as the DTLS client (active role) -- the default when answering a remote offer with a=setup:actpass, which is what browsers always send -- the fingerprint check was skipped on the handshake-completion code path that returns no outgoing packets. This is the most common deployment mode (e.g., an SFU or media server answering a browser's offer).

All released versions prior to 0.15.1 and 0.16.1 are affected. No backports to older lines are planned -- users should upgrade to 0.15.1 or 0.16.1.

Impact

The bug eliminates one half of WebRTC's mutual DTLS authentication. The security of the media and data-channel encryption then rests entirely on the remote peer's fingerprint check.

On its own, the bug does not allow:

  • Passive eavesdropping on SRTP media.
  • A network-positioned attacker to intercept media against a standards-compliant browser peer over a TLS-protected signalling channel -- the browser's fingerprint check prevents the second leg of the MITM from succeeding.

The bug does enable a full MITM on media and data channels when combined with any of:

  • Insecure signalling (HTTP / plain WebSocket) allowing SDP rewrite in transit.
  • A compromised or malicious signalling server.
  • A peer implementation with a similar fingerprint-validation gap.

Both audio/video media (SRTP) and data channels (SCTP-over-DTLS) are affected.

Patches

  • 0.15.1 (for the 0.15.x line)
  • 0.16.1 (for the 0.16.x line)

Workarounds

None. Upgrade is required.

Resources

Database specific
{
    "cwe_ids":  [
        "CWE-295"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-08T17:08:18Z",
    "nvd_published_at":  "2026-05-14T21:16:47Z",
    "severity":  "HIGH"
}
References

Affected packages

Hex / ex_webrtc

Package

Name
ex_webrtc
Purl
pkg:hex/ex_webrtc

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.15.1

Affected versions

0.*
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.7.0
0.8.0
0.8.1
0.9.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qwfw-ggxw-577c/GHSA-qwfw-ggxw-577c.json"

Hex / ex_webrtc

Package

Name
ex_webrtc
Purl
pkg:hex/ex_webrtc

Affected ranges

Type
SEMVER
Events
Introduced
0.16.0
Fixed
0.16.1

Affected versions

0.*
0.16.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qwfw-ggxw-577c/GHSA-qwfw-ggxw-577c.json"