Memory Exhaustion Vulnerability in Coturn TURN and STUN Server
CVE-2026-73214
8.2HIGH
What is CVE-2026-73214?
The Coturn TURN and STUN Server prior to version 4.16.0 contains a vulnerability that allows an unauthenticated remote sender to exploit the dtls_server_input_handler() and create_new_connected_udp_socket() functions, leading to potential memory exhaustion. By sending a specially crafted fragmented ClientHello which improperly retains the OpenSSL dtls1_reassemble_fragment() state, an attacker can exhaust server memory, causing disruptions and performance degradation. This issue has been addressed in version 4.16.0.
Affected Version(s)
coturn < 4.16.0
