Coturn是Coturn组织开源的一款TURN(VoIP媒体业务NAT穿越服务器和网关)和STUN(用户数据报协议简单穿越网络地址转换器)Server的实现。 Coturn 4.13.1之前版本存在安全漏洞,该漏洞源于src/server/ns_turn_server.c中的good_peer_addr()函数在调用src/client/ns_turn_ioaddr.c中的ioa_addr_in_range()时未对IPv4兼容、6to4和64:ff9b::/96 NAT64地址形式进行规范化,可导致经
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73214 | 8.2 HIGH | coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling so |
| CVE-2026-73215 | 7.1 HIGH | The coturn server can end in a state where it does not accept more requests with "even-por |
| CVE-2026-73216 | 6.5 MEDIUM | coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity |
| CVE-2026-73213 | 5.8 MEDIUM | Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic |
No comments yet