Search CVE reports


Toggle filters

1 – 10 of 26 results


CVE-2026-68555

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-68554

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-68553

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string()...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-68552

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-73216

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-73215

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-73214

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment()...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-73213

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(),...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-73212

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible,...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-65981

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against...

1 affected package

coturn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
coturn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages