Unbounded Session Vulnerability in Coturn TURN/STUN Server by Coturn
CVE-2026-68555
6.5MEDIUM
What is CVE-2026-68555?
A security flaw in Coturn version 4.15.0 allows an authenticated TURN user to create unbounded server-side sessions by repeatedly resuming an allocation without completing the handoff when the server's mobility feature is enabled. The bug arises due to a failure to appropriately handle allocation timeouts and pending sessions, leading to potential server memory exhaustion even with strict user quotas in place. This issue was addressed in version 4.16.0.
Affected Version(s)
coturn >= 4.15.0, < 4.16.0
