Heap Memory Disclosure Vulnerability in Coturn by Coturn Project
CVE-2026-62959

8.2HIGH

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
31 July 2026

What is CVE-2026-62959?

A vulnerability exists in Coturn when it is configured with --acme-redirect and uses a plaintext-TCP listener, leading to a potential leak of sensitive data. An unauthenticated remote client can exploit this issue by sending a simple HTTP GET request, receiving a response that may expose up to 870 bytes of sensitive heap memory. This leaked memory can contain data from other clients, including TURN credentials and OAuth tokens, due to improper memory handling. This issue affects Coturn versions 4.5.2 through 4.14.0 and is resolved in version 4.15.0.

Affected Version(s)

coturn >= 4.5.2, < 4.15.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.