CVE-2026-68554
Reported by GitHub_M · Published August 19, 2026
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, and recompute the unkeyed FINGERPRINT while the original HMAC remains valid because it covers only the message prefix. Server-side parsing in src/server/ns_turn_server.c continues past MESSAGE-INTEGRITY through handle_turn_allocate(), handle_turn_create_permission(), handle_turn_refresh(), and handle_turn_command(), allowing trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject a permission, or bypass the origin check. TLS and DTLS deployments prevent this in-transit modification. This issue is fixed in version 4.15.0.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| coturn | coturn | < 4.15.0 |
| coturn | coturn | < 4.15.0, < 4.15.0 |
Timeline
- Aug 19, 2026 CVE Published
- Aug 20, 2026 Coalition ESS Score
- Aug 20, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 10, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
References
- https://github.com/coturn/coturn/security/advisories/GHSA-5538-7cxj-5jcc x_refsource_CONFIRM
- https://github.com/coturn/coturn/commit/ab762f334f511ea37ab4b703a47d5d683a5be978 x_refsource_MISC
- https://github.com/coturn/coturn/releases/tag/4.15.0 x_refsource_MISC