Coturn-project
2 CVEs tracked since 2020. Since Feb 2020, none of them reached CISA KEV.
Coturn-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-02 | 2 | 0 |
Products
The products that kept showing up in Coturn-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 14 most recently published vulnerabilities affecting Coturn-project.
- CVE-2026-53450Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection7.4
- CVE-2026-53449Coturn: Arbitrary File Write via CLI psd Command6.0
- CVE-2026-53448Coturn: SQL Injection in HTTPS Admin Panel Delete Operations7.2
- CVE-2026-43994Coturn: Stack buffer overflow in decode_oauth_token_gcm()8.1
- CVE-2026-43915Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username5.4
- CVE-2026-40613Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)7.5
- CVE-2026-27624Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL7.2
- CVE-2020-26262Loopback bypass in Coturn7.2
- CVE-2020-4067Improper Initialization in coturn7.0
- CVE-2020-6061An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other ...9.8
- CVE-2020-6062An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service...7.5
- CVE-2018-4059An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin por...9.8
- CVE-2018-4058An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loo...7.7
- CVE-2018-4056An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL inj...9.8
The record
- Peak rank
- #153 in Feb 2020
- Busiest month shown
- Feb 2020, 2 CVEs
- Months with a KEV entry
- 0 since Feb 2020
- Monthly snapshots
- 1 since 2020