PT-2026-70831 · Coturn · Coturn
CVE-2026-73216
·
Published
2026-08-11
·
Updated
2026-08-27
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Coturn versions prior to 4.17.0
Description
The
shutdown client connection() function in src/server/ns turn server.c prematurely calls dec quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation. Because the allocation, relay socket, session, and mobility ticket are preserved, an authenticated client can bypass the --user-quota and --total-quota restrictions, potentially leading to the exhaustion of relay ports.Recommendations
Update to version 4.17.0.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coturn