Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wormhole App
Wormhole App wormhole |
|
| Vendors & Products |
Wormhole App
Wormhole App wormhole |
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP. | |
| Title | Wormhole.app SSRF | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T19:44:16.396Z
Reserved: 2026-09-25T16:34:02.240Z
Link: CVE-2026-100251
No data.
Status : Deferred
Published: 2026-10-01T20:17:20.707
Modified: 2026-10-01T20:37:52.400
Link: CVE-2026-100251
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:47:40Z
Weaknesses