coturn
Networking Infrastructureoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting coturn.
- CVE-2026-68555coturn: Chained mobility resumes allow authenticated remote memory exhaustion6.5
- CVE-2026-68552Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass5.3
- CVE-2026-68554Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
- CVE-2026-68553Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command7.1
- CVE-2026-73216coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity6.5
- CVE-2026-73215The coturn server can end in a state where it does not accept more requests with "even-port" enabled.
- CVE-2026-73214coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS
- CVE-2026-73213Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)
- CVE-2026-73212coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE
- CVE-2026-65981Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover7.1
- CVE-2026-62959Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)
- CVE-2026-53450Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection7.4
- CVE-2026-53449Coturn: Arbitrary File Write via CLI psd Command6.0
- CVE-2026-53448Coturn: SQL Injection in HTTPS Admin Panel Delete Operations7.2
- CVE-2026-43994Coturn: Stack buffer overflow in decode_oauth_token_gcm()8.1