PT-2026-66853 · Coturn · Coturn

CVE-2026-62959

·

Published

2026-07-31

·

Updated

2026-08-27

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Coturn versions 4.5.2 through 4.14.0
Description When started with the --acme-redirect parameter and exposing a plaintext-TCP listener, an unauthenticated remote client can send an HTTP GET request to trigger a memory leak. The server responds with a 301 redirect where the Location header contains up to approximately 870 bytes of adjacent process heap memory. This occurs because a recycled network receive buffer is reused without being zeroed due to a signed-to-unsigned conversion error. On active servers, this leaked memory may contain sensitive data from other clients, such as TURN credentials, OAuth tokens, or relayed payloads.
Recommendations Update Coturn to version 4.15.0.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62959
GHSA-M23X-5QF5-988G
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn