IPv6 Relay Vulnerability in Coturn Open Source Server
CVE-2026-73213
5.8MEDIUM
What is CVE-2026-73213?
The Coturn TURN and STUN server, prior to version 4.16.0, is susceptible to an improper input validation vulnerability. The addr_less_eq() function in src/client/ns_turn_ioaddr.c permits an authenticated TURN client to relay communication to an IPv6 peer incorrectly categorized within a defined non-prefix-aligned denied-peer-ip range. This misclassification stems from a flawed component-wise comparison in the ioa_addr_in_range() function. Users are advised to upgrade to version 4.16.0 or later to mitigate this issue.
Affected Version(s)
coturn < 4.16.0
