Coturn Project
Coturn Project Coturn: vulnerabilidades y CVE
Coturn Project Coturn tiene 14 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses7
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-53450 | Alta (7.4) | 0.29% | — | 10 jul 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by… |
| CVE-2026-53449 | Media (6) | 0.21% | — | 10 jul 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation.… |
| CVE-2026-53448 | Alta (7.2) | 0.70% | — | 10 jul 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without… |
| CVE-2026-43994 | Crítica (9.8) | 0.68% | — | 18 jun 2026 | Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth… |
| CVE-2026-43915 | Media (5.4) | 0.24% | — | 18 jun 2026 | Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN… |
| CVE-2026-40613 | Alta (7.5) | 1.5% | — | 21 abr 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment… |
| CVE-2026-27624 | Media (6.5) | 0.45% | — | 25 feb 2026 | Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262… |
| CVE-2020-26262 | Alta (7.2) | 1.5% | — | 13 ene 2021 | Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it… |
| CVE-2020-4067 | Alta (7.5) | 1.9% | — | 29 jun 2020 | In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use… |
| CVE-2020-6062 | Alta (7.5) | 6.1% | — | 19 feb 2020 | An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to… |
| CVE-2020-6061 | Crítica (9.8) | 5.1% | — | 19 feb 2020 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An… |
| CVE-2018-4059 | Crítica (9.8) | 1.9% | — | 21 mar 2019 | An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback… |
| CVE-2018-4058 | Alta (7.7) | 0.92% | — | 21 mar 2019 | An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loopback interface of its… |
| CVE-2018-4056 | Crítica (9.8) | 3.0% | — | 5 feb 2019 | An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in… |