---
id: CVE-2026-104074
title: >-
  Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that
  allows remote unauthenticated attackers to leak stack memory contents by
  sending a TURN Allocate request without credentials
summary: >-
  Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that
  allows remote unauthenticated attackers to leak stack memory contents by
  sending a TURN Allocate request without credentials. Attackers can exploit the
  stun_ini…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-908
vendor: coturn
product: coturn
affected:
  - coturn >= 4.10.0 < 4.11.0
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T15:17:05.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104074'
references:
  - url: >-
      https://github.com/coturn/coturn/commit/741b2983cc52f967dd08c438fd72a5f08f13ca27
    label: disclosure@vulncheck.com
  - url: 'https://github.com/coturn/coturn/pull/1878'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/coturn/coturn/releases/tag/4.11.0'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T15:36:04.050Z'
---

## Overview

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
