Format String Vulnerability in Coturn TURN and STUN Server by Coturn
CVE-2026-68553

7.1HIGH

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-68553?

Coturn, an open-source implementation of TURN and STUN servers, has a vulnerability in which an authenticated user can input format specifiers in specific attributes. These attributes bypass certain validations and are directly used in Redis commands, potentially leading to unauthorized access to stack memory or service disruptions. This issue can crash the Coturn process, affecting active TURN sessions and compromising data integrity. The vulnerability has been addressed in Coturn version 4.13.0.

Affected Version(s)

coturn < 4.13.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.