{"id":"CVE-2026-104074","title":"Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials","summary":"Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_ini…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-908"],"vendor":"coturn","product":"coturn","affected":["coturn >= 4.10.0 < 4.11.0"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T15:17:05.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104074","references":[{"url":"https://github.com/coturn/coturn/commit/741b2983cc52f967dd08c438fd72a5f08f13ca27","label":"disclosure@vulncheck.com"},{"url":"https://github.com/coturn/coturn/pull/1878","label":"disclosure@vulncheck.com"},{"url":"https://github.com/coturn/coturn/releases/tag/4.11.0","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T15:36:04.050Z","slug":"CVE-2026-104074","body":"## Overview\n\nCoturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}