Executive brief
Coturn is a free TURN/STUN server used for peer-to-peer audio and video communication. An authenticated user can exploit a flaw in the mobility feature to hold multiple relay port allocations despite per-user and system-wide quota limits, eventually exhausting the server's relay port pool and preventing legitimate connections.
Technical details
The vulnerability exists in shutdown_client_connection() in src/server/ns_turn_server.c, where bandwidth accounting and quota are prematurely released during the first-stage close of a mobility-enabled allocation while the allocation, relay socket, session, and mobility ticket remain active and resumable. An authenticated client can repeatedly create mobility allocations over TCP, disconnect, and immediately re-allocate, bypassing --user-quota and --total-quota restrictions. The client can therefore hold many live relay allocations (up to 508 ports) across quota boundaries. The fix, released in version 4.17.0, defers quota and bandwidth release until the final second-stage teardown, ensuring the charge is held for as long as the allocation remains valid and resumable.
Affected products
- Coturn Coturn prior to 4.17.0
Timeline
- 2026-08-11: disclosed: CVE-2026-73216 published
- 2026-08-05: patched: Fixed in version 4.17.0 released 2026-08-05