Coturn是Coturn组织开源的一款实现TURN协议的服务器软件。 Coturn 4.15.0之前版本存在安全漏洞,该漏洞源于STUN消息处理中MESSAGE-INTEGRITY校验不充分,攻击者可在明文UDP或TCP上附加LIFETIME、XOR-PEER-ADDRESS或ORIGIN属性,导致覆盖分配生命周期、注入权限或绕过来源检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68553 | 7.1 HIGH | Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command |
| CVE-2026-68555 | 6.5 MEDIUM | coturn: Chained mobility resumes allow authenticated remote memory exhaustion |
| CVE-2026-68552 | 5.3 MEDIUM | Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypa |
No comments yet