IPv6 Relay Vulnerability in Coturn Open Source Server
CVE-2026-73213

5.8MEDIUM

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73213?

The Coturn TURN and STUN server, prior to version 4.16.0, is susceptible to an improper input validation vulnerability. The addr_less_eq() function in src/client/ns_turn_ioaddr.c permits an authenticated TURN client to relay communication to an IPv6 peer incorrectly categorized within a defined non-prefix-aligned denied-peer-ip range. This misclassification stems from a flawed component-wise comparison in the ioa_addr_in_range() function. Users are advised to upgrade to version 4.16.0 or later to mitigate this issue.

Affected Version(s)

coturn < 4.16.0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.