Description
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Instance Metadata Exposure
Action: Apply Patch
AI Analysis

Impact

The Wormhole.app application, when deployed before 2026‑08‑22, contains a Server Side Request Forgery flaw caused by a misconfigured coturn TURN server that fails to restrict TCP relay peers. An unauthenticated attacker can induce the TURN server to issue requests from the Wormhole relay and thereby read the instance metadata service or create TCP connections that appear to originate from the relay’s IP. This flaw, classified as CWE‑918, enables an attacker to obtain privileged information that may include credentials, configuration data, or other sensitive metadata, potentially facilitating further compromise of the host or network. The vulnerability stems from the TURN server’s lack of peer validation, which permits arbitrary outgoing connections and misleads the Wormhole relay into exposing backend services to external clients. Because the breach does not require authentication or elevated privileges, any user able to send requests to the Wormhole endpoint can trigger the SSRF. In the context of the CVSS framework, the flaw has a base score of 6.9, indicating moderate severity. The attack vector is primarily network‑based, leveraging the exposed Wormhole endpoint to initiate the SSRF. Given the lack of defensive controls in older deployments and the straightforward exploitation path, the risk to systems running an outdated Wormhole app is significant, particularly if the instance metadata endpoint is not isolated.

Affected Systems

The affected vendor and product are Wormhole App, identified as Wormhole. Systems running any version of the Wormhole application before the update released on 2026‑08‑22 are susceptible. These deployments feature the coturn TURN server without proper TCP peer restrictions.

Risk and Exploitability

The CVSS score of 6.9 suggests that the flaw can result in unauthorized data disclosure. While the EPSS score is not available, the lack of a keystone KEV listing indicates that no widespread exploitation is currently documented. The vulnerability’s exploitation does not require authentication or privileged credentials, relying only on the ability to craft a request to the Wormhole service. The network‑level attack path is straightforward: an external client sends a malicious request which the TURN server follows to the instance metadata service or other internal endpoints. The simplicity of the exploit path combined with the absence of mandatory authentication makes a low‑barrier attack likely if the application remains unpatched.

Generated by OpenCVE AI on October 1, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Wormhole App to the 2026‑08‑22 release or later, which corrects the TURN server configuration.
  • Reconfigure the coturn TURN server to enforce strict peer restrictions, allowing connections only from trusted IP ranges.
  • Implement network controls that block outbound requests from the Wormhole environment to the instance metadata service.

Generated by OpenCVE AI on October 1, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
Title Wormhole.app SSRF
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T19:44:16.396Z

Reserved: 2026-09-25T16:34:02.240Z

Link: CVE-2026-100251

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:20.707

Modified: 2026-10-01T20:37:52.400

Link: CVE-2026-100251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:30:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)