Improper access control in coTURN - CVE-2026-27624
Published: April 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass peer IP access control restrictions.
The vulnerability exists due to improper access control in peer address validation in src/client/ns_turn_ioaddr.c when processing CreatePermission or ChannelBind requests with IPv4-mapped IPv6 XOR-PEER-ADDRESS values. A remote attacker can send a specially crafted request using an ::ffff: IPv4-mapped IPv6 peer address to bypass peer IP access control restrictions.
Exploitation may depend on whether the relay socket is wildcard-bound versus bound to a specific IPv6 address, and on operating system behavior.
Affected software
Fedora
coturn
How to mitigate CVE-2026-27624
coturn - addressed in versions 4.9.0-1.el8, 4.9.0-1.el9, 4.9.0-1.el10_1, 4.9.0-1.el10_2, 4.9.0-1.el10_3, 4.9.0-1.fc42, 4.9.0-1.fc43, 4.9.0-1.fc44