VendorscoTURN Projectcoturnall versions
Vulnerabilities

coTURN Project coTURN

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2018-4059
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN server configuration, which can lead to additional attacks. An attacker who can get access to the telnet port can gain administrator access to the TURN server.
Published 2019-03-21 · Modified
10.0EPSS 0.019
CVE-2020-6061
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
Published 2020-02-19 · Modified
9.8EPSS 0.051
CVE-2018-4056
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.
Published 2019-02-05 · Modified
9.8EPSS 0.030
CVE-2026-43994
Coturn: Stack buffer overflow in decode_oauth_token_gcm()
Published 2026-06-18 · Analyzed
9.8EPSS 0.007
CVE-2018-4058
An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loopback interface of its own host. This can provide access to other private services running on that host, which can lead to further attacks. An attacker can set up a relay with a loopback address as the peer on an affected TURN server to trigger this vulnerability.
Published 2019-03-21 · Modified
7.7EPSS 0.009
CVE-2020-6062
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.
Published 2020-02-19 · Modified
7.5EPSS 0.061
CVE-2020-4067
Improper Initialization in coturn
Published 2020-06-29 · Modified
7.5EPSS 0.019
CVE-2026-40613
Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)
Published 2026-04-21 · Analyzed
7.5EPSS 0.015
CVE-2026-53450
Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection
Published 2026-07-10 · Analyzed
7.4EPSS 0.003
CVE-2020-26262
Loopback bypass in Coturn
Published 2021-01-13 · Modified
7.2EPSS 0.013
CVE-2026-53448
Coturn: SQL Injection in HTTPS Admin Panel Delete Operations
Published 2026-07-10 · Analyzed
7.2EPSS 0.007
CVE-2026-27624
Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL
Published 2026-02-25 · Analyzed
7.2EPSS 0.005
CVE-2026-53449
Coturn: Arbitrary File Write via CLI psd Command
Published 2026-07-10 · Analyzed
6.0EPSS 0.002
CVE-2026-43915
Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username
Published 2026-06-18 · Analyzed
5.4EPSS 0.002