CVE-2020-26262Disclosure(coturn_project / coturn)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch coturn_project coturn systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it was observed that when sending a `CONNECT` request with the `XOR-PEER-ADDRESS` value of `0.0.0.0`, a successful response was received and subsequently, `CONNECTIONBIND` also received a successful response. Coturn then is able to relay packets to the loopback interface. Additionally, when coturn is listening on IPv6, which is default, the loopback interface can also be reached by making use of either `[::1]` or `[::]` as the peer address. By using the address `0.0.0.0` as the peer address, a malicious user will be able to relay packets to the loopback interface, unless `--denied-peer-ip=0.0.0.0` (or similar) has been specified. Since the default configuration implies that loopback peers are not allowed, coturn administrators may choose to not set the `denied-peer-ip` setting. The issue patched in version 4.5.2. As a workaround the addresses in the address block `0.0.0.0/8`, `[::1]` and `[::]` should be denied by default unless `--allow-loopback-peers` has been specified.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-682

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coturn
  • fedora

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
coturnfedora

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-25: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-25: 102-1202-25
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Classification over time
DateTotalLabels
2026-02-121
Disclosure1
2026-02-251
Patch1
Full discourse2 posts
  • Enable Security@enablesecurity
    Patch

    coturn 4.9.0 dropped yesterday with fixes for CVE-2026-27624, a bypass of the CVE-2020-26262 fix using IPv4-mapped IPv6 addresses (::ffff:127.0.0.1 bypasses all IPv4 deny rules). The guides cover the workaround for older versions.

    Post summary

    The release of coturn 4.9.0 includes fixes for CVE-2026-27624 and provides guidance on workarounds for older versions, addressing a bypass of the CVE-2020-26262 fix via IPv4‑mapped IPv6 addresses.

    1000065
    344 followersView on X
  • Enable Security@enablesecurity
    Disclosure

    coturn has had 30+ memory safety fixes, a CVSS 9.8 SQL injection, and we found an IPv6 loopback bypass (CVE-2020-26262) where the "protection" against [::1] just.. didn't work.

    Post summary

    The text announces discovery of an IPv6 loopback bypass (CVE‑2020‑26262) in coturn, highlighting a serious vulnerability but providing no evidence of exploitation, patch, or PoC.

    1000068
    344 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appcoturn_projectcoturn---
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--

Explore more