VDB

CVE-2026-68554

CVE-2026-68554 PUBLISHED CVSS 2.3 LOW

Reported by GitHub_M · Published August 19, 2026

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, and recompute the unkeyed FINGERPRINT while the original HMAC remains valid because it covers only the message prefix. Server-side parsing in src/server/ns_turn_server.c continues past MESSAGE-INTEGRITY through handle_turn_allocate(), handle_turn_create_permission(), handle_turn_refresh(), and handle_turn_command(), allowing trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject a permission, or bypass the origin check. TLS and DTLS deployments prevent this in-transit modification. This issue is fixed in version 4.15.0.

Risk Scores

CVSS 4.0
2.3
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
coturncoturn< 4.15.0
coturncoturn< 4.15.0, < 4.15.0

Timeline

  • Aug 19, 2026 CVE Published
  • Aug 20, 2026 Coalition ESS Score
  • Aug 20, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 10, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›