SecAlerts
c

coturn

Security Risk Profile

47
/100
medium

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 21, 2026 to present

17
Total CVEs
9
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
47/100
medium
📈 9 in Last 30 Days

Severity Distribution

Critical
1
High
8
Medium
7
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
SSRF
2
2
Integer Overflow
1
3
SQL Injection
1
4
Buffer Overflow
1
5
XSS
1

Most Affected Products

1. Coturn coturn18
2. Coturn Project Coturn6

Recent Vulnerabilities

See more →
CVE-2026-68555
CVSS 6.5medium

coturn: Chained mobility resumes allow authenticated remote memory exhaustion

Aug 19, 2026🔧 No Patch
CVE-2026-68552
CVSS 5.3medium

Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass

Aug 19, 2026🔧 No Patch
CVE-2026-68554
CVSS 2.3low

Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests

Aug 19, 2026🔧 No Patch
CVE-2026-68553
CVSS 7.1high

Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command

Aug 19, 2026🔧 No Patch
CVE-2026-73216
CVSS 6.5medium

coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity

Aug 11, 2026🔧 No Patch
CVE-2026-73215
CVSS 7.1high

The coturn server can end in a state where it does not accept more requests with "even-port" enabled.

Aug 11, 2026🔧 No Patch
CVE-2026-73214
CVSS 8.2high

coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS

Aug 11, 2026🔧 No Patch
CVE-2026-73213
CVSS 5.8medium

Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)

Aug 11, 2026🔧 No Patch
CVE-2026-73212
CVSS 5.8medium

coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE

Aug 11, 2026🔧 No Patch
CVE-2026-65981
CVSS 7.1high

Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover

Jul 31, 2026🔧 No Patch

Monitor coturn in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.