Intel

AIKIDO-2026-10045

github.com/pion/webrtc/v4 is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

35

Low Risk

This Affects:

GOgithub.com/pion/webrtc/v4
4.0.0 - 4.2.1
Fixed in 4.2.2

TL;DR

Affected versions of this package are vulnerable to crashes and panics caused by improper input validation in the OGG and IVF readers, where malformed or untrusted media inputs can trigger divide-by-zero errors and other panic conditions.

Who does this affect?

You are affected if you are using a version of this package 4.2.2.

Background info

github.com/pion/webrtc/v4 is vulnerable to Improper Input Validation in versions 4.0.0 - 4.2.1.

How to fix this

Upgrade the github.com/pion/webrtc/v4 library to the patch version.