Coturn
Vendor:
First CVE: Feb 5, 2019 · Active for 7 years
14
Total CVEs
More Total CVEs than 91% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Coturn over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 5, 2019
7 years ago
Most Recent CVE
Jul 10, 2026
14 days ago
CVE Severity & Scoring
Coturn14 CVEs
21%
50%
29%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low3 (21.4%)
High2 (14.3%)
None9 (64.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43994CRITICAL Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len fiel | Jun 18, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-53450HIGH Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the defau | Jul 10, 2026 | 7.4 | 33 | NO | NO |
CVE-2018-4056CRITICAL An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can | Feb 5, 2019 | 9.8 | 32 | NO | NO |
CVE-2026-53448HIGH Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprin | Jul 10, 2026 | 7.2 | 31 | NO | NO |
CVE-2018-4059CRITICAL An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated | Mar 21, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-53449MEDIUM Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passe | Jul 10, 2026 | 6.0 | 29 | NO | NO |
CVE-2026-40613HIGH Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t | Apr 21, 2026 | 7.5 | 27 | NO | NO |
CVE-2020-6062HIGH An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and | Feb 19, 2020 | 7.5 | 27 | NO | NO |
CVE-2026-43915MEDIUM Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS inter | Jun 18, 2026 | 5.4 | 26 | NO | NO |
CVE-2020-6061CRITICAL An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information | Feb 19, 2020 | 9.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Coturn
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.5.1.1 | 2 | 8.7 | 5.6% | 0 | 0 |