PT-2026-78699 · Coturn · Coturn

CVE-2026-68554

·

Published

2026-08-19

·

Updated

2026-08-27

CVSS v4.0

2.3

Low

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.15.0
Description An on-path attacker can modify authenticated STUN requests sent over plain UDP or TCP by appending attributes after the MESSAGE-INTEGRITY attribute and adjusting the STUN header length. Because the HMAC only covers the message prefix, the original HMAC remains valid while the unkeyed FINGERPRINT is recomputed. Server-side parsing in src/server/ns turn server.c continues processing through the handle turn allocate(), handle turn create permission(), handle turn refresh(), and handle turn command() functions. This allows trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject permissions, or bypass origin checks. Deployments using TLS or DTLS prevent this modification.
Recommendations Update to version 4.15.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68554
GHSA-5538-7CXJ-5JCC
OPENSUSE-SU-2026:11617-1

Affected Products

Coturn