VYPR
Unrated severityNVD Advisory· Published Aug 1, 2026

Debian coturn: Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.…

CVE-2026-65981

Description

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.

Affected products

3
  • Coturn/Coturninferred2 versions
    <4.15.0+ 1 more
    • (no CPE)range: <4.15.0
    • (no CPE)range: <4.15.0
  • Debian/coturnllm-create
    Range: <4.15.0

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.

CVE-2026-65981 · VYPR