{"schema_version":1,"title":"Coturn vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Coturn: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73216, was published on 11 August 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/coturn","json_url":"https://junglewise.ai/threats/vendors/coturn.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/coturn","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":12,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":12},"latest":[{"cve":"CVE-2026-73216","cvss":6.5,"epss":0.0057,"slug":"cve-2026-73216-coturn-quota-bypass-in-mobility-enabled-allocations","title":"Coturn quota bypass in mobility-enabled allocations","severity":"medium","exploited":false,"published_at":"2026-08-11T18:18:27.04+00:00","url":"https://junglewise.ai/threats/cve-2026-73216-coturn-quota-bypass-in-mobility-enabled-allocations"},{"cve":"CVE-2026-73215","cvss":0,"epss":0.0045,"slug":"cve-2026-73215-coturn-even-port-relay-port-exhaustion","title":"Coturn EVEN-PORT relay port exhaustion","severity":"info","exploited":false,"published_at":"2026-08-11T18:18:26.91+00:00","url":"https://junglewise.ai/threats/cve-2026-73215-coturn-even-port-relay-port-exhaustion"},{"cve":"CVE-2026-73214","cvss":7.5,"epss":0.0058,"slug":"cve-2026-73214-coturn-dtls-memory-exhaustion-via-fragmented-clienthello","title":"Coturn DTLS memory exhaustion via fragmented ClientHello","severity":"info","exploited":false,"published_at":"2026-08-11T18:18:26.773+00:00","url":"https://junglewise.ai/threats/cve-2026-73214-coturn-dtls-memory-exhaustion-via-fragmented-clienthello"},{"cve":"CVE-2026-73213","epss":0.0041,"slug":"cve-2026-73213-coturn-ipv6-range-check-bypass-in-turn-relay","title":"Coturn IPv6 range check bypass in TURN relay","severity":"info","exploited":false,"published_at":"2026-08-11T18:18:26.64+00:00","url":"https://junglewise.ai/threats/cve-2026-73213-coturn-ipv6-range-check-bypass-in-turn-relay"},{"cve":"CVE-2026-73212","cvss":0,"epss":0.005,"slug":"cve-2026-73212-coturn-turn-stun-relay-acl-bypass-via-ipv6-address-encoding","title":"Coturn TURN/STUN relay ACL bypass via IPv6 address encoding","severity":"info","exploited":false,"published_at":"2026-08-11T18:18:26.49+00:00","url":"https://junglewise.ai/threats/cve-2026-73212-coturn-turn-stun-relay-acl-bypass-via-ipv6-address-encoding"},{"cve":"CVE-2026-65981","cvss":7.1,"slug":"cve-2026-65981-coturn-authorization-bypass-in-mice-mobility-session-resumption","title":"Coturn authorization bypass in MICE mobility session resumption","severity":"high","exploited":false,"published_at":"2026-07-31T21:17:31.857+00:00","url":"https://junglewise.ai/threats/cve-2026-65981-coturn-authorization-bypass-in-mice-mobility-session-resumption"},{"cve":"CVE-2026-62959","cvss":8.2,"slug":"cve-2026-62959-coturn-heap-memory-disclosure-in-acme-redirect","title":"Coturn heap memory disclosure in ACME redirect","severity":"info","exploited":false,"published_at":"2026-07-31T20:16:53.357+00:00","url":"https://junglewise.ai/threats/cve-2026-62959-coturn-heap-memory-disclosure-in-acme-redirect"},{"cve":"CVE-2026-53450","cvss":7.4,"slug":"cve-2026-53450-coturn-loopback-protection-bypass-via-ipv4-mapped-ipv6-addresses","title":"Coturn loopback protection bypass via IPv4-mapped IPv6 addresses","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:24.193+00:00","url":"https://junglewise.ai/threats/cve-2026-53450-coturn-loopback-protection-bypass-via-ipv4-mapped-ipv6-addresses"},{"cve":"CVE-2026-53449","cvss":6,"slug":"cve-2026-53449-coturn-arbitrary-file-write-in-cli-psd-command","title":"Coturn arbitrary file write in CLI psd command","severity":"medium","exploited":false,"published_at":"2026-07-10T19:17:24.073+00:00","url":"https://junglewise.ai/threats/cve-2026-53449-coturn-arbitrary-file-write-in-cli-psd-command"},{"cve":"CVE-2026-53448","cvss":7.2,"slug":"cve-2026-53448-coturn-sql-injection-in-https-admin-panel-delete-operations","title":"Coturn SQL injection in HTTPS admin panel delete operations","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:23.93+00:00","url":"https://junglewise.ai/threats/cve-2026-53448-coturn-sql-injection-in-https-admin-panel-delete-operations"},{"cve":"CVE-2026-43994","cvss":8.1,"slug":"cve-2026-43994-coturn-stack-buffer-overflow-in-decode-oauth-token-gcm","title":"Coturn stack buffer overflow in decode_oauth_token_gcm","severity":"high","exploited":false,"published_at":"2026-06-18T21:16:28.63+00:00","url":"https://junglewise.ai/threats/cve-2026-43994-coturn-stack-buffer-overflow-in-decode-oauth-token-gcm"},{"cve":"CVE-2026-43915","cvss":5.4,"slug":"cve-2026-43915-coturn-stored-xss-in-web-admin-interface-via-turn-username","title":"Coturn stored XSS in web-admin interface via TURN username","severity":"medium","exploited":false,"published_at":"2026-06-18T20:16:13.287+00:00","url":"https://junglewise.ai/threats/cve-2026-43915-coturn-stored-xss-in-web-admin-interface-via-turn-username"}],"vendor":{"hub":true,"name":"Coturn","slug":"coturn","homepage":"https://github.com/coturn/coturn","description":"coturn is an open-source project that provides an implementation of TURN and STUN servers for VoIP and WebRTC.","url":"https://junglewise.ai/threats/vendors/coturn"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-43994","cvss":8.1,"slug":"cve-2026-43994-coturn-stack-buffer-overflow-in-decode-oauth-token-gcm","title":"Coturn stack buffer overflow in decode_oauth_token_gcm","severity":"high","exploited":false,"published_at":"2026-06-18T21:16:28.63+00:00","url":"https://junglewise.ai/threats/cve-2026-43994-coturn-stack-buffer-overflow-in-decode-oauth-token-gcm"},{"cve":"CVE-2026-53450","cvss":7.4,"slug":"cve-2026-53450-coturn-loopback-protection-bypass-via-ipv4-mapped-ipv6-addresses","title":"Coturn loopback protection bypass via IPv4-mapped IPv6 addresses","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:24.193+00:00","url":"https://junglewise.ai/threats/cve-2026-53450-coturn-loopback-protection-bypass-via-ipv4-mapped-ipv6-addresses"},{"cve":"CVE-2026-53448","cvss":7.2,"slug":"cve-2026-53448-coturn-sql-injection-in-https-admin-panel-delete-operations","title":"Coturn SQL injection in HTTPS admin panel delete operations","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:23.93+00:00","url":"https://junglewise.ai/threats/cve-2026-53448-coturn-sql-injection-in-https-admin-panel-delete-operations"},{"cve":"CVE-2026-65981","cvss":7.1,"slug":"cve-2026-65981-coturn-authorization-bypass-in-mice-mobility-session-resumption","title":"Coturn authorization bypass in MICE mobility session resumption","severity":"high","exploited":false,"published_at":"2026-07-31T21:17:31.857+00:00","url":"https://junglewise.ai/threats/cve-2026-65981-coturn-authorization-bypass-in-mice-mobility-session-resumption"},{"cve":"CVE-2026-73216","cvss":6.5,"epss":0.0057,"slug":"cve-2026-73216-coturn-quota-bypass-in-mobility-enabled-allocations","title":"Coturn quota bypass in mobility-enabled allocations","severity":"medium","exploited":false,"published_at":"2026-08-11T18:18:27.04+00:00","url":"https://junglewise.ai/threats/cve-2026-73216-coturn-quota-bypass-in-mobility-enabled-allocations"},{"cve":"CVE-2026-53449","cvss":6,"slug":"cve-2026-53449-coturn-arbitrary-file-write-in-cli-psd-command","title":"Coturn arbitrary file write in CLI psd command","severity":"medium","exploited":false,"published_at":"2026-07-10T19:17:24.073+00:00","url":"https://junglewise.ai/threats/cve-2026-53449-coturn-arbitrary-file-write-in-cli-psd-command"},{"cve":"CVE-2026-43915","cvss":5.4,"slug":"cve-2026-43915-coturn-stored-xss-in-web-admin-interface-via-turn-username","title":"Coturn stored XSS in web-admin interface via TURN username","severity":"medium","exploited":false,"published_at":"2026-06-18T20:16:13.287+00:00","url":"https://junglewise.ai/threats/cve-2026-43915-coturn-stored-xss-in-web-admin-interface-via-turn-username"},{"cve":"CVE-2026-62959","cvss":8.2,"slug":"cve-2026-62959-coturn-heap-memory-disclosure-in-acme-redirect","title":"Coturn heap memory disclosure in ACME redirect","severity":"info","exploited":false,"published_at":"2026-07-31T20:16:53.357+00:00","url":"https://junglewise.ai/threats/cve-2026-62959-coturn-heap-memory-disclosure-in-acme-redirect"},{"cve":"CVE-2026-73214","cvss":7.5,"epss":0.0058,"slug":"cve-2026-73214-coturn-dtls-memory-exhaustion-via-fragmented-clienthello","title":"Coturn DTLS memory exhaustion via fragmented ClientHello","severity":"info","exploited":false,"published_at":"2026-08-11T18:18:26.773+00:00","url":"https://junglewise.ai/threats/cve-2026-73214-coturn-dtls-memory-exhaustion-via-fragmented-clienthello"},{"cve":"CVE-2026-73212","cvss":0,"epss":0.005,"slug":"cve-2026-73212-coturn-turn-stun-relay-acl-bypass-via-ipv6-address-encoding","title":"Coturn TURN/STUN relay ACL bypass via IPv6 address encoding","severity":"info","exploited":false,"published_at":"2026-08-11T18:18:26.49+00:00","url":"https://junglewise.ai/threats/cve-2026-73212-coturn-turn-stun-relay-acl-bypass-via-ipv6-address-encoding"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Coturn","slug":"coturn","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/coturn"}]}