CVE-2026-53450Patch(coturn_project / coturn)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch coturn_project coturn systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a TURN XOR-PEER-ADDRESS attribute. ioa_addr_is_loopback checks for the literal IPv6 loopback shape before IPv4-mapped IPv6 handling, so good_peer_addr does not apply the default loopback rejection and an authenticated TURN client can expose services bound only to localhost on the coturn host through TURN relay traffic. This issue is fixed in version 4.13.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coturn

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
coturn

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 106-30
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Enable Security@enablesecurity
    Patch

    3/ coturn shipped new hardening defaults (4.13.1/4.14.0, including a native amplification rate limit) plus three more CVEs, including a default loopback bypass (CVE-2026-53450). We refreshed our coturn security configuration guide to match.

    Post summary

    Coturn released hardening defaults to mitigate CVE-2026-53450 and updated its security configuration guide accordingly.

    1000082
    357 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcoturn_projectcoturn---

Explore more