PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104074 coturn CVE debrief

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. This vulnerability affects Coturn deployments, particularly those using version 4.10.0. The vulnerability class is related to the handling of memory in the stun_init_error_response_common_str() function. The likely operational impact includes the exposure of stack memory contents, which can weaken ASLR and enable precise version fingerprinting. The source confidence is high based on the CVE Program record and NIST NVD detail page.

Vendor
coturn
Product
Unknown
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Coturn 4.10.0 deployment contexts; verify exposure, assess compensating controls, and apply patch or upgrade to Coturn 4.11.0 or later. Operators of Coturn deployments should verify their version and assess their exposure. Vulnerability management and security teams should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

Why it matters

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents; defenders should verify exposure, assess compensating controls, and apply patch or upgrade to Coturn 4.11.0 or later.

  • Remote unauthenticated attackers can leak stack memory contents
  • Exposed pointer fragments weaken ASLR and enable precise version fingerprinting
  • Verify Coturn version and assess exposure in deployment contexts
  • Implement compensating controls to restrict unauthorized access

Technical summary

The stun_init_error_response_common_str() function in src/client/ns_turn_msg.c fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase. This oversight allows remote unauthenticated attackers to leak stack memory contents. The affected product context is Coturn version 4.10.0, and the defensive impact includes the potential exposure of sensitive memory information. The source-grounded technical framing indicates that the vulnerability is related to the improper handling of memory in the stun_init_error_response_common_str() function.

Defensive priority

Medium priority for Coturn 4.10.0 deployment contexts; verify exposure, assess compensating controls

Recommended defensive actions

  • Verify Coturn version and assess exposure in deployment contexts
  • Implement compensating controls to restrict unauthorized access
  • Monitor for potential exploitation attempts
  • Apply patch or upgrade to Coturn 4.11.0 or later
  • Review and update asset inventory to ensure accurate tracking of affected systems
  • Track exceptions and retest remediated assets to ensure successful patching
  • technicalSummary

Evidence notes

Official CVE Program record and NIST NVD detail page provide vulnerability metadata; Coturn 4.11.0 release notes, pull request, and patch commit offer remediation details. The Coturn 4.11.0 release notes provide information on the patch, and the pull request and patch commit offer technical details on the fix. The vulnerability affects Coturn version 4.10.0, and defenders should verify exposure and assess compensating controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104074 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104074

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104074 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104074

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104074.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coturn/coturn/releases/tag/4.11.0

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coturn/coturn/pull/1878

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coturn/coturn/commit/741b2983cc52f967dd08c438fd72a5f08f13ca27

    Supplemental source - patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.