CVE-2026-68553: Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command

Published Aug 19, 2026
·
Updated

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes issecurestring() validation and is embedded into Redis keys at nine call sites in src/apps/relay/nsioalibengineimpl.c. sendmessagetoredis() in src/apps/relay/hiredislibevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the valist. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.

Affected Software

1 affected component
Coturn coturn<4.13.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade coturn to a version that resolves this vulnerability.

    Fixed in 4.13.0
  2. Compensating control

    If upgrading to coturn 4.13.0 is not immediately possible, mitigate impact by preventing access to the coturn TURN service from untrusted networks/clients (e.g., restrict TURN ports/management access via firewall/ACL) to reduce exposure to authenticated attackers able to inject malicious STUN USERNAME/REALM values.

Event History

Aug 19, 2026
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated TURN user can exploit it by placing printf-style format specifiers in STUN USERNAME or REALM attributes. The attack is network-reachable and does not require user interaction.

2

What impact should operators expect from successful exploitation?

Exploitation can crash the Coturn process, terminating active TURN sessions. It may also disclose stack memory into Redis.

3

Are deployments using Redis affected?

The vulnerable path embeds attacker-controlled USERNAME or REALM values into Redis keys and sends them through hiredis. Deployments using the affected Coturn versions prior to 4.13.0 should update to 4.13.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203