PatchSiren cyber security CVE debrief
CVE-2026-68552 coturn CVE debrief
The Coturn implementation of TURN and STUN Server is vulnerable to a denial of service attack. An unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() to wrap when STUN_HEADER_LENGTH is added. This leads to desynchronization of the stream parser and dropping of the attacking client's connection. Coturn versions prior to 4.15.0 are affected. Administrators and users of Coturn versions prior to 4.15.0 should be aware of this vulnerability and take necessary actions to mitigate potential denial of service attacks. This includes updating Coturn to version 4.15.0 or later and monitoring for suspicious STUN message activity.
- Vendor
- coturn
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-09
Who should care
Administrators and users of Coturn versions prior to 4.15.0 should be aware of this vulnerability and take necessary actions to mitigate potential denial of service attacks. This includes updating Coturn to version 4.15.0 or later and monitoring for suspicious STUN message activity. Security teams and operators managing Coturn deployments should prioritize this vulnerability based on the CVSS score of 5.3 and the potential for denial of service attacks.
Technical summary
The Coturn implementation of TURN and STUN Server is vulnerable to a denial of service attack. An unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() to wrap when STUN_HEADER_LENGTH is added. This leads to desynchronization of the stream parser and dropping of the attacking client's connection. Coturn versions prior to 4.15.0 are affected.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential for denial of service attacks.
Recommended defensive actions
- Update Coturn to version 4.15.0 or later
- Monitor for suspicious STUN message activity
- Implement compensating controls to mitigate potential denial of service attacks
- Review Coturn version and monitor for suspicious activity
- Confirm whether affected Coturn deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from the NVD and CVE.org indicates that Coturn versions prior to 4.15.0 are vulnerable to a denial of service attack. The issue is caused by improper handling of STUN messages, which can lead to desynchronization of the stream parser and dropping of the attacking client's connection. Limited source detail suggests verifying Coturn version and monitoring for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68552 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68552
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68552 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68552
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/commit/ed32e1fb6c843f9cf9a28d91c541dfbf40874f25
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/pull/1964
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/releases/tag/4.15.0
-
Source reference
Unverified legacy reference
URL: https://github.com/coturn/coturn/security/advisories/GHSA-m562-mf7x-q7rr
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.