Coturn
This hub aggregates every CVE we track for Coturn, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
3
Critical
11
High
0
In CISA KEV
Severity distribution
HIGH11CRITICAL3MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
1
0
2
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Coturn.
- CVE-2026-65981Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover7.1
- CVE-2026-53450Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection7.4
- CVE-2026-53449Coturn: Arbitrary File Write via CLI psd Command6.0
- CVE-2026-53448Coturn: SQL Injection in HTTPS Admin Panel Delete Operations7.2
- CVE-2026-43994Coturn: Stack buffer overflow in decode_oauth_token_gcm()8.1
- CVE-2026-43915Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username5.4
- CVE-2026-40613Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)7.5
- CVE-2026-27624Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL7.2
- CVE-2025-69217Coturn has unsafe nonce and relay port randomization due to weak random number generation.7.7
- CVE-2020-26262Loopback bypass in Coturn7.2
- CVE-2020-4067Improper Initialization in coturn7.0
- CVE-2020-6061An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other ...9.8
- CVE-2020-6062An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service...7.5
- CVE-2018-4059An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin por...9.8
- CVE-2018-4058An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loo...7.7
Product normalization is registry-driven with AI assist and human review. How it works