CVE-2026-104074: Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE

Published Oct 7, 2026
·
Updated

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stuniniterrorresponsecommonstr() function in src/client/nsturnmsg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.

Affected Software

1 affected component
Coturn coturn=4.10.0

Event History

Oct 7, 2026
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Coturn 4.10.0 deployments that accept remote TURN Allocate requests are exposed. The request can be sent without credentials, so authentication does not protect the affected error-response path.

2

What does an attacker need to exploit it?

An attacker needs network access to send a TURN Allocate request to the Coturn service. No valid credentials or user interaction are required.

3

What information can be disclosed?

The ERROR-CODE reason phrase can contain uninitialized stack memory, including pointer fragments. This may weaken ASLR and allow more precise version fingerprinting.

4

What should be done if patching is not immediately possible?

The provided data identifies unauthenticated remote Allocate requests as the trigger. Restricting network access to the TURN service can reduce exposure until an update is applied.

5

Which release addresses the issue?

The references point to the Coturn 4.11.0 release and the associated fix commit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203