Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-65981

Опубликовано: 31 июл. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.

A flaw was found in Coturn, an open-source implementation of TURN and STUN servers. An authenticated attacker who obtains a victim's MOBILITY-TICKET can exploit this vulnerability during a session resume. This allows the attacker to take over the victim's TURN (Traversal Using Relays around NAT) allocation. As a result, the attacker can receive and inject relayed network traffic, and consume the victim's allocated resources.

Отчет

This flaw affects the community-maintained coturn TURN/STUN server as shipped in Fedora and EPEL. Red Hat does not ship coturn in any core Red Hat product. Fedora and EPEL currently ship coturn 4.16.0, which already includes the fix released in 4.15.0, so the shipped builds are not vulnerable.

Меры по смягчению последствий

No action needed - the shipped coturn build (4.16.0) already contains the upstream fix.

Дополнительная информация

Статус:

Important
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2509934coturn: Coturn: Authorization bypass allows session takeover via MOBILITY-TICKET session resume

EPSS

Процентиль: 16%
0.0025
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 месяца назад

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.

CVSS3: 7.1
nvd
около 1 месяца назад

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.

CVSS3: 7.1
debian
около 1 месяца назад

Coturn is a free open source implementation of TURN and STUN Server. P ...

EPSS

Процентиль: 16%
0.0025
Низкий

7.1 High

CVSS3