Junglewise Threat Intelligence

CVE-2026-73214: Coturn DTLS memory exhaustion via fragmented ClientHello

CVE-2026-73214 · Severity: info · CVSS 7.5 · Published 2026-08-11

Technologies: Coturn. Vendors: Coturn.

Executive brief

Coturn is a widely-used open source TURN/STUN server for enabling peer-to-peer communication through firewalls and NATs. An unauthenticated remote attacker can send specially crafted DTLS handshake messages that cause the server to allocate excessive memory, leading to denial of service without requiring valid credentials or completing the handshake process.

Technical details

The vulnerability exists in dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c. The DTLS listener allocates per-peer SSL state and OpenSSL's dtls1_reassemble_fragment() begins buffering fragments before cookie validation occurs. An attacker can send a 35-byte fragmented ClientHello declaring a 650,000-byte handshake, causing OpenSSL to allocate large buffers for each fragment without the attacker needing to provide credentials, complete the handshake, validate a cookie, or even use consistent source addresses. An attacker sending datagrams from many spoofed addresses can exhaust server memory. The fix (version 4.16.0) caps the number of concurrent half-open DTLS handshakes globally across relay threads and requires reservation before allocating per-peer state.

Affected products

  • Coturn Coturn before 4.16.0

Timeline

  • 2026-07-26: patched: Fix committed to repository
  • 2026-08-11: disclosed: CVE-2026-73214 published

References

Related threats