Coturn / Coturn
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-68555 | coturn: Chained mobility resumes allow authenticated remote memory exhaustion | MEDIUM | 6.5 | Aug 19, 2026 |
| CVE-2026-68552 | Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass | MEDIUM | 5.3 | Aug 19, 2026 |
| CVE-2026-68554 | Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests | LOW | 2.3 | Aug 19, 2026 |
| CVE-2026-68553 | Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command | HIGH | 7.1 | Aug 19, 2026 |
| CVE-2026-73216 | coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity | MEDIUM | 6.5 | Aug 11, 2026 |
| CVE-2026-73215 | The coturn server can end in a state where it does not accept more requests with "even-port" enabled. | HIGH | 7.1 | Aug 11, 2026 |
| CVE-2026-73214 | coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS | HIGH | 8.2 | Aug 11, 2026 |
| CVE-2026-73213 | Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`al… | MEDIUM | 5.8 | Aug 11, 2026 |
| CVE-2026-73212 | coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE | MEDIUM | 5.8 | Aug 11, 2026 |
| CVE-2026-65981 | Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover | HIGH | 7.1 | Jul 31, 2026 |
| CVE-2026-62959 | Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`) | HIGH | 8.2 | Jul 31, 2026 |
| CVE-2026-53450 | Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection | HIGH | 7.4 | Jul 10, 2026 |
| CVE-2026-53449 | Coturn: Arbitrary File Write via CLI psd Command | MEDIUM | 6.0 | Jul 10, 2026 |
| CVE-2026-53448 | Coturn: SQL Injection in HTTPS Admin Panel Delete Operations | HIGH | 7.2 | Jul 10, 2026 |
| CVE-2026-43994 | Coturn: Stack buffer overflow in decode_oauth_token_gcm() | CRITICAL | 9.8 | Jun 18, 2026 |
| CVE-2026-43915 | Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username | MEDIUM | 5.4 | Jun 18, 2026 |
| CVE-2026-40613 | Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64) | HIGH | 7.5 | Apr 21, 2026 |
| CVE-2026-27624 | Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL | HIGH | 7.2 | Feb 25, 2026 |
| CVE-2025-69217 | Coturn has unsafe nonce and relay port randomization due to weak random number generation. | HIGH | 7.7 | Dec 30, 2025 |
| CVE-2020-26262 | Loopback bypass in Coturn | HIGH | 7.2 | Jan 13, 2021 |
| CVE-2020-4067 | Improper Initialization in coturn | HIGH | 7.5 | Jun 29, 2020 |
| CVE-2020-6061 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request ca… | CRITICAL | 9.8 | Feb 19, 2020 |
| CVE-2020-6062 | An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead… | HIGH | 7.5 | Feb 19, 2020 |
| CVE-2018-4059 | An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server ru… | CRITICAL | 9.8 | Mar 21, 2019 |
| CVE-2018-4058 | An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allow… | HIGH | 7.7 | Mar 21, 2019 |
Showing 1 to 25 of 26 CVEs