Resource exhaustion in coTURN - CVE-2026-68555
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the mobility resume transition handling in src/server/ns_turn_server.c when processing chained authenticated mobility resume requests. A remote user can repeatedly resume one allocation from new UDP 5-tuples without completing the handoff to cause a denial of service.
Only deployments with the --mobility feature enabled are affected, and the issue can persist even when the allocation quota is set to one.