CVE-2026-44700

Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments, but enables a full man-in-the-middle attack when chained with insecure signalling or a peer with similar validation gaps. This vulnerability is fixed in 0.15.1 and 0.16.1.
CVSS

No CVSS.

Configurations

No configuration.

History

14 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 21:16

Updated : 2026-05-15 14:53


NVD link : CVE-2026-44700

Mitre link : CVE-2026-44700

CVE.ORG link : CVE-2026-44700


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation