CVE Tools

Coturn

26 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Coturn, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Coturn CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Coturn CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-021
2026-030
2026-041
2026-050
2026-062
2026-075
2026-089
2026-090

Severity

How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical315%
  • High1260%
  • Medium525%

Latest CVEs

The 15 most recently published vulnerabilities affecting Coturn.

  1. CVE-2026-68555coturn: Chained mobility resumes allow authenticated remote memory exhaustion6.5
  2. CVE-2026-68552Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass5.3
  3. CVE-2026-68554Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests—
  4. CVE-2026-68553Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command7.1
  5. CVE-2026-73216coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity6.5
  6. CVE-2026-73215The coturn server can end in a state where it does not accept more requests with "even-port" enabled.—
  7. CVE-2026-73214coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS—
  8. CVE-2026-73213Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)—
  9. CVE-2026-73212coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE—
  10. CVE-2026-65981Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover7.1
  11. CVE-2026-62959Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)—
  12. CVE-2026-53450Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection7.4
  13. CVE-2026-53449Coturn: Arbitrary File Write via CLI psd Command6.0
  14. CVE-2026-53448Coturn: SQL Injection in HTTPS Admin Panel Delete Operations7.2
  15. CVE-2026-43994Coturn: Stack buffer overflow in decode_oauth_token_gcm()8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store