Coturn是Coturn组织开源的一款TURN(VoIP媒体业务NAT穿越服务器和网关)和STUN(用户数据报协议简单穿越网络地址转换器)Server的实现。 Coturn 4.17.0之前版本存在资源管理错误漏洞,该漏洞源于shutdown_client_connection()过早调用dec_quota()并释放带宽计费,可能导致已认证客户端绕过用户配额和总配额,耗尽中继端口。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73214 | 8.2 HIGH | coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling so |
| CVE-2026-73215 | 7.1 HIGH | The coturn server can end in a state where it does not accept more requests with "even-por |
| CVE-2026-73212 | 5.8 MEDIUM | coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path |
| CVE-2026-73213 | 5.8 MEDIUM | Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic |
No comments yet