VDB

CVE-2026-43915

CVE-2026-43915 PUBLISHED CVSS 5.4 MEDIUM

Reported by GitHub_M · Published June 18, 2026

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that executes when an authenticated web-admin user views the TURN session list. In configurations using anonymous TURN access (--no-auth), this may be exploitable without TURN credentials. In authenticated deployments, exploitation requires valid TURN credentials or control over a provisioned username. This issue has been fixed in version 4.11.0.

Risk Scores

CVSS 3.1
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
coturncoturn< 4.11.0
coturncoturn< 4.11.0

Timeline

  • Jun 18, 2026 CVE Published
  • Jun 18, 2026 CVE Updated
  • Jun 19, 2026 Coalition ESS Score
  • Jun 23, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 1, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›