Security Vulnerability in Coturn TURN and STUN Server Affects Bandwidth Accounting
CVE-2026-73216
6.5MEDIUM
What is CVE-2026-73216?
A vulnerability in Coturn, an open-source implementation of TURN and STUN server, allows authenticated clients to bypass user and total quotas due to a flaw in the shutdown_client_connection() function. This issue arises when bandwidth accounting is improperly released during the first-stage close of a mobility-enabled allocation. As a result, the allocation, relay socket, session, and mobility ticket remain intact, enabling clients to exhaust relay ports. The issue has been addressed in Coturn version 4.17.0.
Affected Version(s)
coturn < 4.17.0
