PT-2026-78699 · Coturn · Coturn
CVE-2026-68554
·
Published
2026-08-19
·
Updated
2026-08-27
CVSS v4.0
2.3
Low
| Vector | AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Coturn versions prior to 4.15.0
Description
An on-path attacker can modify authenticated STUN requests sent over plain UDP or TCP by appending attributes after the MESSAGE-INTEGRITY attribute and adjusting the STUN header length. Because the HMAC only covers the message prefix, the original HMAC remains valid while the unkeyed FINGERPRINT is recomputed. Server-side parsing in
src/server/ns turn server.c continues processing through the handle turn allocate(), handle turn create permission(), handle turn refresh(), and handle turn command() functions. This allows trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject permissions, or bypass origin checks. Deployments using TLS or DTLS prevent this modification.Recommendations
Update to version 4.15.0.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coturn