Allocation of Resources Without Limits or Throttling in coTURN - #VU140948
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the DTLS listener session handling in src/apps/relay/dtls_listener.c when processing initial fragmented ClientHello messages before DTLS cookie validation. A remote attacker can send specially crafted UDP datagrams from fresh source tuples to cause a denial of service.
DTLS must be enabled with a certificate and private key. No TURN credential, completed handshake, valid cookie, source-address spoofing, or response processing is required, and a single host can vary its UDP source port to create distinct tuples.