Incorrect authorization in coTURN - #VU140951

 

Incorrect authorization in coTURN - #VU140951

Published: August 5, 2026


Vulnerability identifier: #VU140951
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass IPv6 peer address restrictions and reach an intended-denied service through TURN relaying.

The vulnerability exists due to incorrect authorization in addr_less_eq() in src/client/ns_turn_ioaddr.c when evaluating non-prefix-aligned IPv6 min-max peer ranges. A remote user can send CONNECT and CONNECTION-BIND requests for a crafted IPv6 peer address to bypass IPv6 peer address restrictions and reach an intended-denied service through TURN relaying.

Exploitation requires a custom non-prefix-aligned IPv6 min-max rule and a reachable peer service from the Coturn server. Exact-address and ordinary prefix-aligned controls are not affected in the same way.


Affected software

coTURN

Remediation

Install security update from vendor's website.

coTURN - update to 4.16.0

External References

Related Security Bulletins