Medium severity5.3NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-104074
CVE-2026-104074
Description
Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.