🔐 CVE Alert

CVE-2026-62959

UNKNOWN 0.0

Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301 response whose Location header contains up to ~870 bytes of adjacent process heap memory. The leaked region is a recycled network receive buffer that is reused without being zeroed, so on a busy server it can contain data from other clients' requests (TURN credentials, OAuth tokens, relayed payloads). Root cause is a signed→unsigned conversion. This issue is fixed in version 4.15.0.

CWE CWE-125 CWE-195
Vendor coturn
Product coturn
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for coturn coturn

Be the first to know when new unknown vulnerabilities affecting coturn coturn are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

coturn / coturn
>= 4.5.2, < 4.15.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/coturn/coturn/security/advisories/GHSA-m23x-5qf5-988g github.com: https://github.com/coturn/coturn/pull/1965 github.com: https://github.com/coturn/coturn/commit/960835886692fa04cf63ddd970c3f330740c87f4 github.com: https://github.com/coturn/coturn/releases/tag/4.15.0