๐Ÿ” CVE Alert

CVE-2026-73212

UNKNOWN 0.0

coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path โ†’ internal-network SSRF and proven internal root RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms, allowing an authenticated RFC 6062 TCP CONNECT relay client to bypass an IPv4 denied-peer-ip range when the Coturn host has a useful translation route. This issue is fixed in version 4.13.1.

CWE CWE-284 CWE-918
Vendor coturn
Product coturn
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for coturn coturn

Be the first to know when new unknown vulnerabilities affecting coturn coturn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

coturn / coturn
< 4.13.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/coturn/coturn/security/advisories/GHSA-2x4g-wx24-48m4 github.com: https://github.com/coturn/coturn/pull/1945 github.com: https://github.com/coturn/coturn/pull/1947 github.com: https://github.com/coturn/coturn/commit/cf4b4952de48510d38415b96300da5fc674bfdda github.com: https://github.com/coturn/coturn/commit/d49ee56aa9fe748af064853d5e430eec1ccc3cbc github.com: https://github.com/coturn/coturn/releases/tag/4.13.1