Format string error in coTURN - CVE-2026-68553
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to use of externally-controlled format string in hiredis Redis command handling when processing crafted TURN USERNAME or REALM attributes in Redis-backed allocation reporting. A remote user can send crafted authentication values containing format specifiers to disclose sensitive information and cause a denial of service.
Exploitation requires valid low-privilege TURN credentials and a coTURN deployment configured with Redis statistics integration.