๐Ÿ” CVE Alert

CVE-2026-73213

UNKNOWN 0.0

Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.

CWE CWE-863
Vendor coturn
Product coturn
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for coturn coturn

Be the first to know when new unknown vulnerabilities affecting coturn coturn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

coturn / coturn
< 4.16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/coturn/coturn/security/advisories/GHSA-4v97-rxjj-4f99 github.com: https://github.com/coturn/coturn/commit/6c13608c28a04af5d63abddd7565a0dcc4771c28 github.com: https://github.com/coturn/coturn/releases/tag/4.16.0