Uninitialized Memory Disclosure in Coturn Product from Coturn
CVE-2026-104074

6.9MEDIUM

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-104074?

Coturn 4.10.0 is susceptible to an uninitialized memory disclosure vulnerability, enabling remote unauthenticated attackers to leak sensitive stack memory contents. This is achieved by sending a TURN Allocate request without the necessary credentials. The flaw is located in the stun_init_error_response_common_str() function within the source file ns_turn_msg.c, where the avalue buffer is not properly initialized. Consequently, when calculating the buffer's length with strlen() and copying from an uninitialized section, attackers can expose fragments of pointers. This leakage can significantly weaken Address Space Layout Randomization (ASLR) and facilitate precise version fingerprinting, posing a security risk to affected systems.

Affected Version(s)

coturn 4.10.0 < 4.11.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Powis of VulnCheck
.