Authentication Bypass in Coturn TURN and STUN Server Affects Multiple Versions
CVE-2026-73212
5.8MEDIUM
What is CVE-2026-73212?
Coturn, a popular open-source implementation of TURN and STUN servers, has a vulnerability where the function good_peer_addr() does not properly canonicalize certain IP address formats in its range-checking logic, specifically for IPv4-compatible, 6to4, and NAT64 address forms. This flaw allows an authenticated TCP CONNECT relay client to bypass restrictions set by the denied-peer-ip range when the Coturn server has an accessible translation route. To mitigate this issue, it is crucial to upgrade to version 4.13.1 or later, which addresses this vulnerability comprehensively.
Affected Version(s)
coturn < 4.13.1
