coturn
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 21, 2026 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →coturn: Chained mobility resumes allow authenticated remote memory exhaustion
Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass
Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command
coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity
The coturn server can end in a state where it does not accept more requests with "even-port" enabled.
coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS
Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)
coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE
Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover
Monitor coturn in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.