PT-2026-78697 · Coturn · Coturn

CVE-2026-68552

·

Published

2026-08-19

·

Updated

2026-08-27

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.15.0
Description An unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field between 65520 and 65532. This causes the len variable in the stun get message len str() function to wrap when the STUN HEADER LENGTH is added. Consequently, the framing layer consumes only 4 to 16 bytes and treats the remaining data as a separate message, which desynchronizes the stream parser and results in the connection of the attacking client being dropped. Other clients and the server process remain unaffected.
Recommendations Update to version 4.15.0.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68552
GHSA-M562-MF7X-Q7RR
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn