๐Ÿ” CVE Alert

CVE-2026-73214

UNKNOWN 0.0

coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0.

CWE CWE-400 CWE-770
Vendor coturn
Product coturn
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for coturn coturn

Be the first to know when new unknown vulnerabilities affecting coturn coturn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

coturn / coturn
< 4.16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/coturn/coturn/security/advisories/GHSA-5x2p-4vqj-f6m4 github.com: https://github.com/coturn/coturn/pull/2003 github.com: https://github.com/coturn/coturn/pull/2012 github.com: https://github.com/coturn/coturn/commit/37e13d1d60af8f1422c01b5e9f1c6bc355d03b85 github.com: https://github.com/coturn/coturn/commit/beb4de9dcb6a475129595b943c9a34264420df09 github.com: https://github.com/coturn/coturn/releases/tag/4.16.0