VYPR

rpm package

opensuse/coturn&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/coturn&distro=openSUSE%20Tumbleweed

Vulnerabilities (22)

  • CVE-2026-68555MedAug 19, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables --mobility. mobile_begin_transition() in src/server/ns_turn

  • CVE-2026-68554LowAug 19, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, and recompute the unkeyed FINGERPRINT while

  • CVE-2026-68553HigAug 19, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine ca

  • CVE-2026-68552MedAug 19, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() in src

  • CVE-2026-73216MedAug 11, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation while pr

  • CVE-2026-73215HigAug 11, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request with reservation bit R=0 even though no RTCP socket

  • CVE-2026-73214HigAug 11, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declarin

  • CVE-2026-73213MedAug 11, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6

  • CVE-2026-73212MedAug 11, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms, allowi

  • CVE-2026-65981HigJul 31, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authen

  • CVE-2026-62959HigJul 31, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301 r

  • CVE-2026-53450HigJul 10, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a T

  • CVE-2026-53449MedJul 10, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrar

  • CVE-2026-53448HigJul 10, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secure_string filter that protects the STUN pro

  • CVE-2026-43994HigJun 18, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access token (0-65535) is passed directly to memcpy() as the

  • CVE-2026-43915MedJun 18, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/Jav

  • CVE-2026-40613HigApr 21, 2026
    affected < 4.17.2-1.1fixed 4.17.2-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a crafted STUN message with odd-aligned at

  • CVE-2026-27624HigFeb 25, 2026
    affected < 4.9.0-1.1fixed 4.9.0-1.1

    Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving "0.0.0.0", "[::1]" and "[::]", but IPv

  • CVE-2025-69217HigDec 30, 2025
    affected < 4.9.0-1.1fixed 4.9.0-1.1

    coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random number generator for nonces and port randomization after refactoring. Additionally, random numbers aren't generated with openssl's RAND_bytes but libc's random

  • CVE-2020-26262HigJan 13, 2021
    affected < 4.5.2-2.2fixed 4.5.2-2.2

    Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it was observed that when sending a `CONNECT` request with the `

Page 1 of 2