CVE-2026-53448
Reported by GitHub_M · Published July 10, 2026
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secure_string filter that protects the STUN protocol path is not applied to the admin panel's delete-user, delete-secret, and delete-IP operations, so an authenticated admin can inject arbitrary SQL through the du, ds, and dip parameters, gaining full database control and potentially OS-level access via PostgreSQL COPY TO PROGRAM. This issue is fixed in version 4.12.0.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| coturn | coturn | < 4.12.0 |
| coturn | coturn | < 4.12.0, < 4.12.0 |
Timeline
- Jul 10, 2026 CVE Published
- Jul 11, 2026 EPSS Score
- Jul 11, 2026 Coalition ESS Score
- Jul 16, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 28, 2026 Security Advisory
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
References
- https://github.com/coturn/coturn/security/advisories/GHSA-v8hj-2xx7-xmp5 x_refsource_CONFIRM
- https://github.com/coturn/coturn/pull/1924 x_refsource_MISC
- https://github.com/coturn/coturn/commit/b84dbab1d1aa6e2bf0211a1cdbb250d6de2a0d09 x_refsource_MISC
- https://github.com/coturn/coturn/releases/tag/4.12.0 x_refsource_MISC