PT-2026-70831 · Coturn · Coturn

CVE-2026-73216

·

Published

2026-08-11

·

Updated

2026-08-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.17.0
Description The shutdown client connection() function in src/server/ns turn server.c prematurely calls dec quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation. Because the allocation, relay socket, session, and mobility ticket are preserved, an authenticated client can bypass the --user-quota and --total-quota restrictions, potentially leading to the exhaustion of relay ports.
Recommendations Update to version 4.17.0.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73216
GHSA-F6HC-79W3-P8PQ
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn