VDB

CVE-2026-68553

CVE-2026-68553 PUBLISHED CVSS 7.1 HIGH

Reported by GitHub_M · Published August 19, 2026

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Affected Products

VendorProductVersions
coturncoturn< 4.13.0
coturncoturn< 4.13.0, < 4.13.0

Timeline

  • Aug 19, 2026 CVE Published
  • Aug 20, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 CVE Updated
  • Sep 10, 2026 EPSS Score
  • Sep 15, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›