Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coturn — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting coturn. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Coturn is an open-source STUN/TURN server implementation that enables NAT traversal for WebRTC and other real-time communication applications. Historically, it has been vulnerable to multiple remote code execution flaws, cross-site scripting attacks, and privilege escalation issues due to input validation failures and insecure default configurations. The project has addressed five CVEs to date, with several RCE vulnerabilities allowing unauthenticated attackers to execute arbitrary code through specially crafted packets. While no major public security incidents have been documented, the persistent discovery of critical vulnerabilities in its networking components highlights the importance of regular updates and hardening for production deployments.

Found 17 results / 17Clear Filters
Top products by coturn: coturn
CVE IDTitleCVSSSeverityPublished
CVE-2026-73216 coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity — coturnCWE-400 6.5 Medium2026-08-11
CVE-2026-73215 The coturn server can end in a state where it does not accept more requests with "even-port" enabled. — coturnCWE-400 7.1 High2026-08-11
CVE-2026-73214 coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS — coturnCWE-400 8.2 High2026-08-11
CVE-2026-73213 Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF) — coturnCWE-863 5.8 Medium2026-08-11
CVE-2026-73212 coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE — coturnCWE-284 5.8 Medium2026-08-11
CVE-2026-65981 Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover — coturnCWE-639 7.1 High2026-07-31
CVE-2026-62959 Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`) — coturnCWE-125 8.2 High2026-07-31
CVE-2026-53450 Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection — coturnCWE-918 7.4 High2026-07-10
CVE-2026-53449 Coturn: Arbitrary File Write via CLI psd Command — coturnCWE-73 6.0 Medium2026-07-10
CVE-2026-53448 Coturn: SQL Injection in HTTPS Admin Panel Delete Operations — coturnCWE-89 7.2 High2026-07-10
CVE-2026-43994 Coturn: Stack buffer overflow in decode_oauth_token_gcm() — coturnCWE-120 8.1 High2026-06-18
CVE-2026-43915 Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username — coturnCWE-79 5.4 Medium2026-06-18
CVE-2026-40613 Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64) — coturnCWE-704 7.5 High2026-04-21
CVE-2026-27624 Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL — coturnCWE-284 7.2 High2026-02-25
CVE-2025-69217 Coturn has unsafe nonce and relay port randomization due to weak random number generation. — coturnCWE-338 7.7 High2025-12-30
CVE-2020-26262 Loopback bypass in Coturn — coturnCWE-441 7.2 High2021-01-13
CVE-2020-4067 Improper Initialization in coturn — coturnCWE-665 7.0 High2020-06-29

This page lists every published CVE security advisory associated with coturn. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.