Package
op-geth-evm
Component
github.com/pion/stun/v2
Latest update
Fixed version
1.101702.3-r0
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.101702.3-r0Status
Impact
op-geth is affected by CVE-2026-54909 (GHSA-34rh-wp3j-6cxc), a denial of service in github.com/pion/stun caused by a panic while parsing a malformed STUN address attribute. op-geth imports github.com/pion/stun/v2 v2.0.0 in p2p/nat/stun.go, and the v2 line has no fixed release; the vulnerability is fixed only in the v3 line (v3.1.5 and later). Upstream go-ethereum has already migrated this code to github.com/pion/stun/v3, so remediation requires op-geth to adopt that upstream migration in a future release. Tracking as pending upstream fix.
Status