GHSA-6h6j-pfrh-66v3MediumCVSS 5.3

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.

🔗 References (5)