CVE-2026-53450
Reported by GitHub_M · Published July 10, 2026
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a TURN XOR-PEER-ADDRESS attribute. ioa_addr_is_loopback checks for the literal IPv6 loopback shape before IPv4-mapped IPv6 handling, so good_peer_addr does not apply the default loopback rejection and an authenticated TURN client can expose services bound only to localhost on the coturn host through TURN relay traffic. This issue is fixed in version 4.13.0.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| coturn | coturn | < 4.13.0 |
| coturn | coturn | < 4.13.0 |
Timeline
- Jul 10, 2026 CVE Published
- Jul 11, 2026 EPSS Score
- Jul 11, 2026 Coalition ESS Score
- Jul 16, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 28, 2026 Security Advisory
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score