PT-2026-70828 · Coturn · Coturn

CVE-2026-73213

·

Published

2026-08-11

·

Updated

2026-08-27

CVSS v4.0

5.8

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.16.0
Description The addr less eq() function in src/client/ns turn ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals within ioa addr in range(). This allows an authenticated TURN client to relay traffic to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is incorrectly classified as being outside that range.
Recommendations Update to version 4.16.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73213
GHSA-4V97-RXJJ-4F99
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn