What is CVE-2026-54909?
CVE-2026-54909 is a vulnerability in pion/stun, a Go STUN implementation. Prior to version 3.1.3, the XORMappedAddress.GetFromAs function can panic when parsing a malformed XOR-MAPPED-ADDRESS attribute, leading to remote denial of service. Upgrading to version 3.1.3 fixes this issue.
Azərbaycanca: CVE-2026-54909 pion/stun (Go dilində STUN tətbiqi) kitabxanasında boşluqdur. 3.1.3-dən əvvəlki versiyalarda, XORMappedAddress.GetFromAs funksiyası zədələnmiş XOR-MAPPED-ADDRESS atributunu emal edərkən panic yaradır və uzaqdan xidmət rəddi (DoS) hücumuna səbəb ola bilər. Problemi həll etmək üçün 3.1.3 versiyasına yenilənməlidir.
FAQ2
In which pion/stun component does CVE-2026-54909 occur?
The vulnerability occurs in the XORMappedAddress.GetFromAs function.
What type of attack can CVE-2026-54909 cause?
It can cause a remote denial of service (DoS) attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.