Vulnerabilities in coturn

17 results
Vexday analysis

Coturn registra 10 vulnerabilidades na base, com 6 publicadas nos últimos 90 dias, indicando atividade de descoberta recente. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não há críticas de CVSS 9.0+, reduzindo o risco imediato. A fraqueza dominante é CWE-441 (Unintended Proxy ou Intermediary), típica de serviços de relay, exigindo atenção em configurações de acesso e validação de origem.

CVE-2020-4067HIGHImproper Initialization in coturnEPSS 1.9%CVE-2020-26262HIGHLoopback bypass in CoturnEPSS 1.3%CVE-2026-40613HIGHCoturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)EPSS 1.1%CVE-2026-43994HIGHCoturn: Stack buffer overflow in decode_oauth_token_gcm()EPSS 0.4%CVE-2026-53448HIGHCoturn: SQL Injection in HTTPS Admin Panel Delete OperationsEPSS 0.4%CVE-2026-62959HIGHCoturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)EPSS 0.4%CVE-2025-69217HIGHCoturn has unsafe nonce and relay port randomization due to weak random number generation.EPSS 0.4%CVE-2026-27624HIGHCoturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACLEPSS 0.3%CVE-2026-65981HIGHCoturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeoverEPSS 0.3%CVE-2026-53449MEDIUMCoturn: Arbitrary File Write via CLI psd CommandEPSS 0.2%CVE-2026-43915MEDIUMCoturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN usernameEPSS 0.2%CVE-2026-53450HIGHCoturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protectionEPSS 0.2%CVE-2026-73216MEDIUMcoturn: mobility disconnects bypass allocation quotas and exhaust relay capacityEPSS CVE-2026-73212MEDIUMcoturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCEEPSS CVE-2026-73214HIGHcoturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoSEPSS CVE-2026-73213MEDIUMCoturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)EPSS CVE-2026-73215HIGHThe coturn server can end in a state where it does not accept more requests with "even-port" enabled.EPSS