Sceawere

Vulnerability Detail

CVE-2026-100251UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Wormhole.app Coturn Server Misconfiguration

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Wormhole App
Product
Wormhole
Attack Type
CWE-918 Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-01T20:17:20.707Z",
  "pubdate": "2026-10-01T20:17:20.707Z",
  "executiveSummary": "Wormhole.app versions deployed before 2026-08-22 contain a critical security misconfiguration within the coturn TURN (Traversal Using Relays around NAT) server implementation. The vulnerability arises from a failure to properly restrict TCP relay peer connections, effectively allowing unauthenticated remote attackers to leverage the relay infrastructure for unauthorized activities.\nThis vulnerability exposes the underlying infrastructure to Server-Side Request Forgery (SSRF) and relay abuse. Attackers can interact with internal instance metadata services—such as those provided by cloud providers like AWS, GCP, or Azure—which are typically restricted to the local environment. Furthermore, an attacker can utilize the Wormhole relay's IP address to source arbitrary TCP traffic, enabling the obfuscation of malicious activities or the circumvention of IP-based access control lists (ACLs) and firewall rules.\nBecause the TURN server does not perform sufficient validation on target peer addresses, an attacker can initiate connections to arbitrary internal or external endpoints. The impact is significant, potentially leading to unauthorized data exfiltration, service discovery, or the execution of attacks from a trusted source IP. This flaw requires no prior authentication, significantly increasing the risk to the confidentiality and integrity of the hosting environment.",
  "technicalDetails": "The root cause of this vulnerability is an insecure configuration of the coturn relay server, specifically regarding the handling of relayed TCP connections. Coturn, when not explicitly restricted via 'denied-peer-ip' or 'allowed-peer-ip' configuration directives, can be induced to connect to internal RFC 1918 addresses or sensitive local services.\nThe attack flow begins with an unauthenticated attacker initiating a TURN allocation request via the relay server. Once a session is established, the attacker sends a ChannelBind or Connect request to the relay, specifying a target internal IP address or metadata endpoint (e.g., 169.254.169.254 for cloud environments) as the peer. Because the server lacks peer-restriction mechanisms, it proxies the TCP connection request to the target.\nBy manipulating the TURN protocol, the attacker can force the relay to initiate arbitrary outbound TCP connections. If the relay is hosted in a cloud environment, this bypasses local security boundaries, allowing the attacker to interact directly with the instance metadata service. This can lead to the retrieval of IAM credentials, instance IDs, or security group information, which may facilitate privilege escalation or further lateral movement within the victim's infrastructure.\nBeyond metadata access, the configuration allows the relay to act as an open proxy for general TCP traffic. Attackers can use the Wormhole.app relay IP as a stepping stone to scan internal networks or perform port scanning against third-party targets. This effectively masks the attacker's true origin, attributing the malicious traffic to the infrastructure provider's IP range. The vulnerability is fundamentally a failure to implement proper 'peer-ip' filtering in the coturn configuration file (turnserver.conf). By failing to blacklist private/local network ranges from the relay target list, the application allows unauthorized traffic to traverse network segments that should be isolated from the public internet. No authentication is required for this interaction, as the relay must remain accessible to facilitate legitimate WebRTC traffic, making this a low-barrier-to-entry exploit that yields high-impact reconnaissance and obfuscation capabilities."
}
CVE-2026-100251: Wormhole.app Coturn Server Misconfiguration (MEDIUM Severity, CVSS: 6.5) | Sceawere