Improper Enforcement of Message Integrity During Transmission in a Communication Channel in coTURN - CVE-2026-68554
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify authenticated TURN requests.
The vulnerability exists due to improper enforcement of message integrity during transmission in TURN request attribute parsing when processing STUN attributes that appear after MESSAGE-INTEGRITY. A remote attacker can append crafted attributes to an authenticated request and adjust the STUN header length to modify authenticated TURN requests.
Exploitation requires an on-path position and affects plain UDP and TCP listeners; TLS and DTLS deployments are not affected.