fix(p2p/nat): drop STUN NAT discovery to remove pion/dtls (CVE-2026-26014) - #2
Merged
Merged
Conversation
…6014) pion/stun/v2 pulls in pion/dtls/v2, which is flagged for CVE-2026-26014 (AES-GCM nonce reuse) with no fixed v2 release. STUN NAT discovery is unused in Tenderly deployments (no devp2p), so remove it instead.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
pion/stun/v2 pulls in pion/dtls/v2, flagged for CVE-2026-26014 (AES-GCM nonce reuse) with no fixed v2 release. STUN NAT discovery is unused in Tenderly deployments (no devp2p), so remove it: p2p/nat/stun.go + tests + server list, the
stunarm in nat.Parse, and the NAT flag help text. All pion modules drop out of go.mod.Branched from d010a4e (current tenderly-core pin on this branch). Consumed by Tenderly/tenderly-core#24896.
Tests
go test ./p2p/nat/
Services affected
None directly; tenderly-core binaries via the pin bump.