CVE-2026-104074
Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.
| CWE | CWE-908 |
| Vendor | coturn |
| Product | coturn |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for coturn coturn
Be the first to know when new medium vulnerabilities affecting coturn coturn are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
coturn / coturn
4.10.0 < 4.11.0
References
Credits
๐ Adam Powis of VulnCheck