PT-2026-70828 · Coturn · Coturn
CVE-2026-73213
·
Published
2026-08-11
·
Updated
2026-08-27
CVSS v4.0
5.8
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Coturn versions prior to 4.16.0
Description
The
addr less eq() function in src/client/ns turn ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals within ioa addr in range(). This allows an authenticated TURN client to relay traffic to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is incorrectly classified as being outside that range.Recommendations
Update to version 4.16.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coturn