Uninitialized Memory Disclosure in Coturn Product from Coturn
CVE-2026-104074
What is CVE-2026-104074?
Coturn 4.10.0 is susceptible to an uninitialized memory disclosure vulnerability, enabling remote unauthenticated attackers to leak sensitive stack memory contents. This is achieved by sending a TURN Allocate request without the necessary credentials. The flaw is located in the stun_init_error_response_common_str() function within the source file ns_turn_msg.c, where the avalue buffer is not properly initialized. Consequently, when calculating the buffer's length with strlen() and copying from an uninitialized section, attackers can expose fragments of pointers. This leakage can significantly weaken Address Space Layout Randomization (ASLR) and facilitate precise version fingerprinting, posing a security risk to affected systems.
Affected Version(s)
coturn 4.10.0 < 4.11.0
