Vulnerabilidades em coturn
21 resultadosAnálise Vexday
Coturn registra 10 vulnerabilidades na base, com 6 publicadas nos últimos 90 dias, indicando atividade de descoberta recente. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não há críticas de CVSS 9.0+, reduzindo o risco imediato. A fraqueza dominante é CWE-441 (Unintended Proxy ou Intermediary), típica de serviços de relay, exigindo atenção em configurações de acesso e validação de origem.
CVE-2020-4067HIGHImproper Initialization in coturnEPSS 1.9%CVE-2020-26262HIGHLoopback bypass in CoturnEPSS 1.3%CVE-2026-40613HIGHCoturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)EPSS 1.1%CVE-2026-53448HIGHCoturn: SQL Injection in HTTPS Admin Panel Delete OperationsEPSS 0.7%CVE-2026-43994HIGHCoturn: Stack buffer overflow in decode_oauth_token_gcm()EPSS 0.7%CVE-2026-62959HIGHCoturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)EPSS 0.5%CVE-2026-73214HIGHcoturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoSEPSS 0.4%CVE-2025-69217HIGHCoturn has unsafe nonce and relay port randomization due to weak random number generation.EPSS 0.4%CVE-2026-73216MEDIUMcoturn: mobility disconnects bypass allocation quotas and exhaust relay capacityEPSS 0.4%CVE-2026-73213MEDIUMCoturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)EPSS 0.4%CVE-2026-68555MEDIUMcoturn: Chained mobility resumes allow authenticated remote memory exhaustionEPSS 0.4%CVE-2026-68553HIGHCoturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis CommandEPSS 0.3%CVE-2026-73215HIGHThe coturn server can end in a state where it does not accept more requests with "even-port" enabled.EPSS 0.3%CVE-2026-68552MEDIUMCoturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypassEPSS 0.3%CVE-2026-65981HIGHCoturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeoverEPSS 0.3%CVE-2026-27624HIGHCoturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACLEPSS 0.3%CVE-2026-53450HIGHCoturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protectionEPSS 0.3%CVE-2026-73212MEDIUMcoturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCEEPSS 0.3%CVE-2026-68554LOWCoturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requestsEPSS 0.2%CVE-2026-43915MEDIUMCoturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN usernameEPSS 0.2%