Impact
The Wormhole.app application, when deployed before 2026‑08‑22, contains a Server Side Request Forgery flaw caused by a misconfigured coturn TURN server that fails to restrict TCP relay peers. An unauthenticated attacker can induce the TURN server to issue requests from the Wormhole relay and thereby read the instance metadata service or create TCP connections that appear to originate from the relay’s IP. This flaw, classified as CWE‑918, enables an attacker to obtain privileged information that may include credentials, configuration data, or other sensitive metadata, potentially facilitating further compromise of the host or network. The vulnerability stems from the TURN server’s lack of peer validation, which permits arbitrary outgoing connections and misleads the Wormhole relay into exposing backend services to external clients. Because the breach does not require authentication or elevated privileges, any user able to send requests to the Wormhole endpoint can trigger the SSRF. In the context of the CVSS framework, the flaw has a base score of 6.9, indicating moderate severity. The attack vector is primarily network‑based, leveraging the exposed Wormhole endpoint to initiate the SSRF. Given the lack of defensive controls in older deployments and the straightforward exploitation path, the risk to systems running an outdated Wormhole app is significant, particularly if the instance metadata endpoint is not isolated.
Affected Systems
The affected vendor and product are Wormhole App, identified as Wormhole. Systems running any version of the Wormhole application before the update released on 2026‑08‑22 are susceptible. These deployments feature the coturn TURN server without proper TCP peer restrictions.
Risk and Exploitability
The CVSS score of 6.9 suggests that the flaw can result in unauthorized data disclosure. While the EPSS score is not available, the lack of a keystone KEV listing indicates that no widespread exploitation is currently documented. The vulnerability’s exploitation does not require authentication or privileged credentials, relying only on the ability to craft a request to the Wormhole service. The network‑level attack path is straightforward: an external client sends a malicious request which the TURN server follows to the instance metadata service or other internal endpoints. The simplicity of the exploit path combined with the absence of mandatory authentication makes a low‑barrier attack likely if the application remains unpatched.
OpenCVE Enrichment