Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coturn — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting coturn. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Coturn is an open-source STUN/TURN server implementation that enables NAT traversal for WebRTC and other real-time communication applications. Historically, it has been vulnerable to multiple remote code execution flaws, cross-site scripting attacks, and privilege escalation issues due to input validation failures and insecure default configurations. The project has addressed five CVEs to date, with several RCE vulnerabilities allowing unauthenticated attackers to execute arbitrary code through specially crafted packets. While no major public security incidents have been documented, the persistent discovery of critical vulnerabilities in its networking components highlights the importance of regular updates and hardening for production deployments.

Top products by coturn: coturn
HighGHSA-59bc-7bed-pdqv2026-08-12
Merge commit from fork · coturn/coturn@3c5b261 · GitHub
Critical2026-08-12
coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity · Advisory · coturn/coturn · GitHub
High2026-08-12
Release 4.17.0 · coturn/coturn · GitHub
Medium2026-08-12
DTLS listener: correct the handshake buffer bound and remove the non-functional client-cert path by eakraly · Pull Reque
HighCVE-2026-72142026-08-12
coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exh
High2026-08-12
DTLS: cap concurrent half-open handshakes (pre-cookie state-exhaustio… · coturn/coturn@37e13d1 · GitHub
HighGHSA-beb4de92026-08-12
DTLS listener: correct the handshake buffer bound and remove the non-… · coturn/coturn@beb4de9 · GitHub
High2026-08-12
`addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN cli
High2026-08-12
Merge commit from fork · coturn/coturn@6c13608 · GitHub
High2026-08-12
Merge commit from fork · coturn/coturn@4adbd82 · GitHub
Medium2026-08-12
Canonicalize all IPv4-in-IPv6 encodings before peer-IP checks by eakraly · Pull Request #1945 · coturn/coturn · GitHub
High2026-08-12
coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and pr
High2026-08-12
Canonicalize all IPv4-in-IPv6 encodings before peer-IP checks (#1945) · coturn/coturn@cf4b495 · GitHub
High2026-08-12
Deny link-local / ULA / site-local relay peers by default by eakraly · Pull Request #1947 · coturn/coturn · GitHub
Medium2026-08-12
Deny link-local / ULA / site-local relay peers by default (#1947) · coturn/coturn@d49ee56 · GitHub
High2026-08-01
fix: bind mobility session-resume to the original allocation owner (#… · coturn/coturn@37df051 · GitHub
HighCVE-2020-65812026-08-01
MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover · Advisory · coturn/cotur
HighCVE-2025-02992026-08-01
Pre-authentication heap memory disclosure in coturn ACME redirect (`try_acme_redirect`) · Advisory · coturn/coturn · Git
HighGHSA-m37x-9gf5-889p2026-08-01
fix: reject ACME requests via signed return by eakraly · Pull Request #1965 · coturn/coturn · GitHub
HighCVE-2023-50742026-08-01
fix: reject ACME requests via signed return (#1965) · coturn/coturn@9608358 · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with coturn. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.