Memory Exhaustion Vulnerability in Coturn TURN and STUN Server
CVE-2026-73214

8.2HIGH

Key Information:

Vendor

Coturn

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73214?

The Coturn TURN and STUN Server prior to version 4.16.0 contains a vulnerability that allows an unauthenticated remote sender to exploit the dtls_server_input_handler() and create_new_connected_udp_socket() functions, leading to potential memory exhaustion. By sending a specially crafted fragmented ClientHello which improperly retains the OpenSSL dtls1_reassemble_fragment() state, an attacker can exhaust server memory, causing disruptions and performance degradation. This issue has been addressed in version 4.16.0.

Affected Version(s)

coturn < 4.16.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.