CVE-2026-104074: Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE
Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stuniniterrorresponsecommonstr() function in src/client/nsturnmsg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Coturn 4.10.0 deployments that accept remote TURN Allocate requests are exposed. The request can be sent without credentials, so authentication does not protect the affected error-response path.
What does an attacker need to exploit it?
An attacker needs network access to send a TURN Allocate request to the Coturn service. No valid credentials or user interaction are required.
What information can be disclosed?
The ERROR-CODE reason phrase can contain uninitialized stack memory, including pointer fragments. This may weaken ASLR and allow more precise version fingerprinting.
What should be done if patching is not immediately possible?
The provided data identifies unauthenticated remote Allocate requests as the trigger. Restricting network access to the TURN service can reduce exposure until an update is applied.
Which release addresses the issue?
The references point to the Coturn 4.11.0 release and the associated fix commit.