PT-2026-70829 · Coturn · Coturn

CVE-2026-73214

·

Published

2026-08-11

·

Updated

2026-08-27

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.16.0
Description The dtls server input handler() and create new connected udp socket() functions in src/apps/relay/dtls listener.c retain the state of the OpenSSL dtls1 reassemble fragment() function when processing a 35-byte fragmented ClientHello that declares a 650,000-byte handshake. This occurs before cookie validation, enabling an unauthenticated remote sender to exhaust system memory using fresh UDP tuples without requiring TURN credentials, a completed handshake, a valid cookie, or source spoofing.
Recommendations Update to version 4.16.0.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73214
GHSA-5X2P-4VQJ-F6M4
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn