PatchSiren cyber security CVE debrief
CVE-2026-104074 coturn CVE debrief
Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. This vulnerability affects Coturn deployments, particularly those using version 4.10.0. The vulnerability class is related to the handling of memory in the stun_init_error_response_common_str() function. The likely operational impact includes the exposure of stack memory contents, which can weaken ASLR and enable precise version fingerprinting. The source confidence is high based on the CVE Program record and NIST NVD detail page.
- Vendor
- coturn
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Coturn 4.10.0 deployment contexts; verify exposure, assess compensating controls, and apply patch or upgrade to Coturn 4.11.0 or later. Operators of Coturn deployments should verify their version and assess their exposure. Vulnerability management and security teams should prioritize patching or mitigating this vulnerability to prevent potential exploitation.
Why it matters
Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents; defenders should verify exposure, assess compensating controls, and apply patch or upgrade to Coturn 4.11.0 or later.
- Remote unauthenticated attackers can leak stack memory contents
- Exposed pointer fragments weaken ASLR and enable precise version fingerprinting
- Verify Coturn version and assess exposure in deployment contexts
- Implement compensating controls to restrict unauthorized access
Technical summary
The stun_init_error_response_common_str() function in src/client/ns_turn_msg.c fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase. This oversight allows remote unauthenticated attackers to leak stack memory contents. The affected product context is Coturn version 4.10.0, and the defensive impact includes the potential exposure of sensitive memory information. The source-grounded technical framing indicates that the vulnerability is related to the improper handling of memory in the stun_init_error_response_common_str() function.
Defensive priority
Medium priority for Coturn 4.10.0 deployment contexts; verify exposure, assess compensating controls
Recommended defensive actions
- Verify Coturn version and assess exposure in deployment contexts
- Implement compensating controls to restrict unauthorized access
- Monitor for potential exploitation attempts
- Apply patch or upgrade to Coturn 4.11.0 or later
- Review and update asset inventory to ensure accurate tracking of affected systems
- Track exceptions and retest remediated assets to ensure successful patching
- technicalSummary
Evidence notes
Official CVE Program record and NIST NVD detail page provide vulnerability metadata; Coturn 4.11.0 release notes, pull request, and patch commit offer remediation details. The Coturn 4.11.0 release notes provide information on the patch, and the pull request and patch commit offer technical details on the fix. The vulnerability affects Coturn version 4.10.0, and defenders should verify exposure and assess compensating controls.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104074 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104074
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104074 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104074
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104074.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/releases/tag/4.11.0
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/pull/1878
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/commit/741b2983cc52f967dd08c438fd72a5f08f13ca27
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.