Back

LOW

Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests

Published Aug 19, 2026

Description

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, and recompute the unkeyed FINGERPRINT while the original HMAC remains valid because it covers only the message prefix. Server-side parsing in src/server/ns_turn_server.c continues past MESSAGE-INTEGRITY through handle_turn_allocate(), handle_turn_create_permission(), handle_turn_refresh(), and handle_turn_command(), allowing trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject a permission, or bypass the origin check. TLS and DTLS deployments prevent this in-transit modification. This issue is fixed in version 4.15.0.

Affected products

Remediation

Red Hat statement

Coturn is not shipped in any Red Hat product. The Fedora and EPEL community builds ship coturn version 4.17.2, which already includes the fix for this issue (fixed in 4.15.0) and are therefore not affected.

Red Hat mitigation

Upgrade to coturn version 4.15.0 or later. Deployments using TLS or DTLS transports are not vulnerable to this issue.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 19, 2026
Updated Aug 20, 2026
Reserved Jul 30, 2026
CISA Vulnrichment
Updated Aug 20, 2026
NVD
Status Deferred
Modified Sep 9, 2026
Red Hat
Severity Moderate
Public date Aug 19, 2026