CVE-2026-104074: Coturn

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.

Affected products

  • Coturn Coturn: from 4.10.0, before 4.11.0 (fixed in 4.11.0)

Published 2026-10-07. Last modified 2026-10-07.