CVE-2026-68552: Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass

Published Aug 19, 2026
·
Updated

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16t len variable in stungetmessagelenstr() in src/client/nsturnmsg.c to wrap when STUNHEADERLENGTH is added. The framing layer then consumes only 4 through 16 bytes, treats the remaining bytes as another message, desynchronizes the stream parser, and drops the attacking client's connection. Other clients and the server process are not affected. This issue is fixed in version 4.15.0.

Affected Software

1 affected component
Coturn coturn<4.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade coturn to a version that resolves this vulnerability.

    Fixed in 4.15.0

Event History

Aug 19, 2026
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Coturn versions before 4.15.0 are affected when they accept STUN messages over TCP or TLS. UDP traffic is not identified as affected.

2

What does an attacker need to exploit it?

An unauthenticated remote client only needs network access to send a crafted STUN message over TCP or TLS. No privileges or user interaction are required.

3

What is the practical impact on a Coturn service?

The crafted message desynchronizes the TCP stream parser and causes the attacking client's connection to be dropped. The issue does not affect other clients or the Coturn server process.

4

What should be done if the service cannot be upgraded immediately?

The provided data identifies upgrading to Coturn 4.15.0 as the fix. It does not provide a workaround or mitigation for affected TCP or TLS listeners.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203