PT-2026-70829 · Coturn · Coturn
CVE-2026-73214
·
Published
2026-08-11
·
Updated
2026-08-27
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Coturn versions prior to 4.16.0
Description
The
dtls server input handler() and create new connected udp socket() functions in src/apps/relay/dtls listener.c retain the state of the OpenSSL dtls1 reassemble fragment() function when processing a 35-byte fragmented ClientHello that declares a 650,000-byte handshake. This occurs before cookie validation, enabling an unauthenticated remote sender to exhaust system memory using fresh UDP tuples without requiring TURN credentials, a completed handshake, a valid cookie, or source spoofing.Recommendations
Update to version 4.16.0.
Exploit
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coturn