CVE-2026-40613Disclosure(coturn_project / coturn)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a crafted STUN message with odd-aligned attribute boundaries, this results in misaligned memory reads at ns_turn_msg.c. On ARM64 architectures (AArch64) with strict alignment enforcement, this causes a SIGBUS signal that immediately kills the turnserver process. An unauthenticated remote attacker can crash any ARM64 coturn deployment by sending a single crafted UDP packet. This vulnerability is fixed in 4.10.0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coturn

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-22)
  • 3 total mentions across 2 days

Affected systems

Products
coturn

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 1Mentions · 2026-04-22: 2PoC Mentioned / Linked · 2026-04-22: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 204-2104-22
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-222
Disclosure1PoC1
Full discourse3 posts
  • CypherByte@cypherbyteio
    PoC

    Your VoIP infrastructure just hit a dead end. 📞⛔ A critical misaligned pointer cast vulnerability (CVE-2026-40613) in Coturn allows remote attackers to trigger a SIGBUS crash. By sending a malformed STUN packet, hackers can take down communication servers globally. If you rely on Coturn for WebRTC or VoIP, your service availability is at risk. 🛡️ Technical Deep Dive & PoC: https://www.cypherbyte.io/blog/cve-2026-40613-coturn-stun-misaligned-pointer-cast-sigbus/ #Coturn #DoS #CyberSecurity #InfoSec #WebRTC #ZeroDay

    Post summary

    CVE-2026-40613 is a pointer‑cast flaw in Coturn that can crash the service via malformed STUN packets; a PoC and detailed technical analysis are linked, but no patch or active exploitation is reported.

    0000055
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40613 Unauthenticated Denial of Service in Coturn Prior to 4.10.0 via Misaligned Memory Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40613

    Post summary

    The text announces a new unauthenticated DoS vulnerability in Coturn (prior to version 4.10.0) caused by a misaligned memory access, without providing PoC, exploit code, or patch details.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40613 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts… https://www.cve.org/CVERecord?id=CVE-2026-40613

    Post summary

    The text announces that prior to version 4.10.0, Coturn's STUN/TURN parsing functions performed unsafe pointer casts, signaling a vulnerability identified as CVE‑2026‑40613.

    00000158
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcoturn_projectcoturn---

Explore more