Authentication Bypass in Coturn TURN and STUN Server Affects Multiple Versions
CVE-2026-73212

5.8MEDIUM

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73212?

Coturn, a popular open-source implementation of TURN and STUN servers, has a vulnerability where the function good_peer_addr() does not properly canonicalize certain IP address formats in its range-checking logic, specifically for IPv4-compatible, 6to4, and NAT64 address forms. This flaw allows an authenticated TCP CONNECT relay client to bypass restrictions set by the denied-peer-ip range when the Coturn server has an accessible translation route. To mitigate this issue, it is crucial to upgrade to version 4.13.1 or later, which addresses this vulnerability comprehensively.

Affected Version(s)

coturn < 4.13.1

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.