CVE-2026-27624Patch(coturn_project / coturn)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch coturn_project coturn systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving "0.0.0.0", "[::1]" and "[::]", but IPv4-mapped IPv6 is not covered. When sending a "CreatePermission" or "ChannelBind" request with the "XOR-PEER-ADDRESS" value of "::ffff:127.0.0.1", a successful response is received, even though "127.0.0.0/8" is blocked via "denied-peer-ip". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in "src/client/ns_turn_ioaddr.c" do not check "IN6_IS_ADDR_V4MAPPED". "ioa_addr_is_loopback()" checks "127.x.x.x" (AF_INET) and "::1" (AF_INET6), but not "::ffff:127.0.0.1." "ioa_addr_is_zero()" checks "0.0.0.0" and "::", but not "::ffff:0.0.0.0." "addr_less_eq()" used by "ioa_addr_in_range()" for "denied-peer-ip" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-441

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coturn

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-25); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Products
coturn

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-25: 2Mentions · 2026-03-02: 1Mentions · 2026-03-05: 2Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-05: 2Technical Details · 2026-02-25: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-05: 202-2503-0203-05
Signal classification2 categories
Patch
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-252
General1Patch1
2026-03-021
General1
2026-03-052
Patch2
Full discourse5 posts
  • Enable Security@enablesecurity
    Patch

    coturn 4.9.0 dropped yesterday with fixes for CVE-2026-27624, a bypass of the CVE-2020-26262 fix using IPv4-mapped IPv6 addresses (::ffff:127.0.0.1 bypasses all IPv4 deny rules). The guides cover the workaround for older versions.

    Post summary

    Coturn 4.9.0 release includes fixes for CVE-2026-27624, with guides covering workarounds for older versions.

    1000065
    344 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads-up, #Fedora 42 sysadmins! A new Coturn update (4.9.0) is out and it's a must-have. It patches CVE-2026-27624, a security bypass that lets attackers evade your IP blocks using IPv4-mapped IPv6 addresses. Read more: 👉 https://tinyurl.com/3hcuwjjh #Security https://t.co/KfjgcOwyKw

    Post summary

    The tweet alerts Fedora 42 sysadmins that the latest Coturn update (4.9.0) includes a patch for CVE‑2026‑27624, a bypass allowing attackers to evade IP blocks via IPv4‑mapped IPv6 addresses.

    0000054
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora releases security updates for Coturn TURN Server, addressing CVE-2026-27624 and a critical IPv4-mapped bypass affecting VoIP and network traffic; admins should patch promptly. https://threatcluster.io/cluster/fedora-coturn-security-bypass-vulnerabilities-addressed-in-r-7eedd450

    Post summary

    Fedora has released security updates for Coturn addressing CVE-2026-27624 and an IPv4-mapped bypass, recommending administrators to apply the patches promptly. No evidence of active exploitation, PoC, or debunking is present.

    0000033
    91 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27624 (CVSS:7.2, HIGH) is Analyzed. Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and..https://nvd.nist.gov/vuln/detail/CVE-2026-27624 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27624 with its CVSS score and a link to the NVD entry, but provides no further technical details, exploit code, or mitigation information.

    0000035
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27624 Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or… https://www.cve.org/CVERecord?id=CVE-2026-27624

    Post summary

    The text merely references CVE-2026-27624 in the context of Coturn without providing any technical, exploit, or mitigation details.

    00000102
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcoturn_projectcoturn---

Explore more