Vulnerability Report: GO-2025-3748
- CVE-2025-49140, GHSA-f26w-gh5m-qq77
- Affects: github.com/pion/interceptor
- Published: Jun 10, 2025
Pion Interceptor's improper RTP padding handling allows remote crash for SFU users (DoS) in github.com/pion/interceptor
For detailed information about this vulnerability, visit https://github.com/pion/interceptor/security/advisories/GHSA-f26w-gh5m-qq77.
Affected Packages
-
PathGo VersionsSymbols
-
from v0.1.36 before v0.1.39
Aliases
References
- https://github.com/pion/interceptor/security/advisories/GHSA-f26w-gh5m-qq77
- https://github.com/pion/interceptor/commit/fa5b35ea867389cec33a9c82fffbd459ca8958e5
- https://github.com/pion/interceptor/pull/338
- https://github.com/pion/webrtc/issues/3148
- https://vuln.go.dev/ID/GO-2025-3748.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.