VulnSea

coturn vulnerabilities

CVEs whose affected-version data names the coturn package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-68554Low· 2.3PoC
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, …

Twilightcoturn · coturnEPSS 0.25%via NVD
CVE-2026-68553High· 7.1PoC
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation…

Midnightcoturn · coturnEPSS 0.34%via NVD
CVE-2026-53449Medium· 6.0
2mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated a…

Sunlitcoturn_project · coturnEPSS 0.21%via NVD
CVE-2026-53448High· 7.2
2mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secu…

Twilightcoturn_project · coturnEPSS 0.70%via NVD
coturn vulnerabilities (CVEs) · VulnSea