CVE-2026-73213
Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.
| CWE | CWE-863 |
| Vendor | coturn |
| Product | coturn |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for coturn coturn
Be the first to know when new unknown vulnerabilities affecting coturn coturn are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
coturn / coturn
< 4.16.0