PT-2026-66853 · Coturn · Coturn
CVE-2026-62959
·
Published
2026-07-31
·
Updated
2026-08-27
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Coturn versions 4.5.2 through 4.14.0
Description
When started with the
--acme-redirect parameter and exposing a plaintext-TCP listener, an unauthenticated remote client can send an HTTP GET request to trigger a memory leak. The server responds with a 301 redirect where the Location header contains up to approximately 870 bytes of adjacent process heap memory. This occurs because a recycled network receive buffer is reused without being zeroed due to a signed-to-unsigned conversion error. On active servers, this leaked memory may contain sensitive data from other clients, such as TURN credentials, OAuth tokens, or relayed payloads.Recommendations
Update Coturn to version 4.15.0.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coturn