CVE-2026-104074
Deferred Deferred - Pending Action

Memory Disclosure in Coturn STUN/TURN Server

Vulnerability report for CVE-2026-104074, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
coturn coturn 4.10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104074 is an uninitialized memory disclosure vulnerability in Coturn 4.10.0. Remote unauthenticated attackers can exploit it by sending a TURN Allocate request without credentials. The vulnerability occurs in the stun_init_error_response_common_str() function, which fails to zero-initialize a buffer before using strlen() and copying stack memory contents into an ERROR-CODE reason phrase. This exposes pointer fragments that weaken ASLR and enable version fingerprinting.

Detection Guidance

Detecting this vulnerability requires checking Coturn server version and monitoring for unusual memory leaks or stack disclosures. Verify if your Coturn version is below 4.11.0. Use commands like 'turnserver --version' to check the installed version. Monitor logs for ERROR-CODE responses containing unexpected data or stack traces.

Impact Analysis

An attacker could exploit this to leak sensitive stack memory, including pointers that weaken ASLR protections. This may allow further exploitation of other vulnerabilities or aid in precise version fingerprinting to target specific Coturn deployments. The impact is primarily on confidentiality and system integrity.

Compliance Impact

This vulnerability exposes stack memory contents, which could lead to unauthorized data disclosure. For GDPR, this may violate principles of data confidentiality and integrity. For HIPAA, it risks exposing protected health information if exploited in healthcare environments.

Mitigation Strategies

Upgrade Coturn to version 4.11.0 or later immediately. Disable unauthenticated TURN Allocate requests if possible. Apply network-level restrictions to block suspicious STUN/TURN traffic. Review and update firewall rules to limit exposure of the Coturn service ports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104074. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart