CVE Tools

Coturn

9 CVEs tracked since 2026. Since Aug 2026, none of them reached CISA KEV.

Coturn CVEs per month

Aug 2026 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Coturn CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0890

Products

The products that kept showing up in Coturn's monthly top three, with their CVEs summed over those months.

  1. Coturn91 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Coturn.

  1. CVE-2026-68555coturn: Chained mobility resumes allow authenticated remote memory exhaustion6.5
  2. CVE-2026-68552Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass5.3
  3. CVE-2026-68554Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests—
  4. CVE-2026-68553Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command7.1
  5. CVE-2026-73216coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity6.5
  6. CVE-2026-73215The coturn server can end in a state where it does not accept more requests with "even-port" enabled.—
  7. CVE-2026-73214coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS—
  8. CVE-2026-73213Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)—
  9. CVE-2026-73212coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE—
  10. CVE-2026-65981Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover7.1
  11. CVE-2026-62959Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)—
  12. CVE-2026-53450Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection7.4
  13. CVE-2026-53449Coturn: Arbitrary File Write via CLI psd Command6.0
  14. CVE-2026-53448Coturn: SQL Injection in HTTPS Admin Panel Delete Operations7.2
  15. CVE-2026-43994Coturn: Stack buffer overflow in decode_oauth_token_gcm()8.1

The record

Peak rank
#173 in Aug 2026
Busiest month shown
Aug 2026, 9 CVEs
Months with a KEV entry
0 since Aug 2026
Monthly snapshots
1 since 2026
Coturn's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store