Heap Memory Disclosure Vulnerability in Coturn by Coturn Project
CVE-2026-62959
8.2HIGH
What is CVE-2026-62959?
A vulnerability exists in Coturn when it is configured with --acme-redirect and uses a plaintext-TCP listener, leading to a potential leak of sensitive data. An unauthenticated remote client can exploit this issue by sending a simple HTTP GET request, receiving a response that may expose up to 870 bytes of sensitive heap memory. This leaked memory can contain data from other clients, including TURN credentials and OAuth tokens, due to improper memory handling. This issue affects Coturn versions 4.5.2 through 4.14.0 and is resolved in version 4.15.0.
Affected Version(s)
coturn >= 4.5.2, < 4.15.0
