CVE Tools

Coturn-project

2 CVEs tracked since 2020. Since Feb 2020, none of them reached CISA KEV.

Coturn-project CVEs per month

Feb 2020 to Feb 2020. Point at a month, or focus the strip and use the arrow keys.
Coturn-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0220

Products

The products that kept showing up in Coturn-project's monthly top three, with their CVEs summed over those months.

  1. Coturn21 month

Latest CVEs

The 14 most recently published vulnerabilities affecting Coturn-project.

  1. CVE-2026-53450Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection7.4
  2. CVE-2026-53449Coturn: Arbitrary File Write via CLI psd Command6.0
  3. CVE-2026-53448Coturn: SQL Injection in HTTPS Admin Panel Delete Operations7.2
  4. CVE-2026-43994Coturn: Stack buffer overflow in decode_oauth_token_gcm()8.1
  5. CVE-2026-43915Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username5.4
  6. CVE-2026-40613Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)7.5
  7. CVE-2026-27624Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL7.2
  8. CVE-2020-26262Loopback bypass in Coturn7.2
  9. CVE-2020-4067Improper Initialization in coturn7.0
  10. CVE-2020-6061An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other ...9.8
  11. CVE-2020-6062An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service...7.5
  12. CVE-2018-4059An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin por...9.8
  13. CVE-2018-4058An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loo...7.7
  14. CVE-2018-4056An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL inj...9.8

The record

Peak rank
#153 in Feb 2020
Busiest month shown
Feb 2020, 2 CVEs
Months with a KEV entry
0 since Feb 2020
Monthly snapshots
1 since 2020
Coturn-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store