VYPR

coturn

by Debian

CVEs (2)

  • CVE-2026-65981Aug 1, 2026
    risk 0.00cvss epss

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an…

  • CVE-2026-62959Aug 1, 2026
    risk 0.00cvss epss

    Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301…