PT-2026-21865 · Coturn+1 · Coturn+1

·

CVE-2026-27624

·

Published

2026-02-23

·

Updated

2026-08-17

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.9.0
Description Coturn, a free open source implementation of TURN and STUN Server, is susceptible to a bypass of loopback and internal range restrictions. Specifically, configurations using "denied-peer-ip" to block loopback and internal ranges can be circumvented by sending a "CreatePermission" or "ChannelBind" request with the "XOR-PEER-ADDRESS" value set to "::ffff:127.0.0.1". This is due to insufficient checks for IPv4-mapped IPv6 addresses in the functions ioa addr is loopback(), ioa addr is zero(), and addr less eq() within "src/client/ns turn ioaddr.c" prior to version 4.9.0. The root cause is that these functions do not check for IN6 IS ADDR V4MAPPED.
Recommendations Versions prior to 4.9.0 should be updated to version 4.9.0 or later.

Exploit

Fix

DoS

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04350
CVE-2026-27624
GHSA-6G6J-R9RF-CM7P
GHSA-J8MM-MPF8-GVJG
MGASA-2026-0051
OPENSUSE-SU-2026:10375-1
OPENSUSE-SU-2026:21184-1

Affected Products

Coturn
Red Os