PT-2026-50787 · Coturn · Coturn

Published

2026-06-18

·

Updated

2026-06-18

·

CVE-2026-43994

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coturn versions prior to 4.10.0
Description A stack buffer overflow exists in the decode oauth token gcm() function. A nonce len field, read from an attacker-supplied OAuth access token, is passed to memcpy() as the copy length into a 256-byte stack buffer (oauth encrypted block.nonce[256]) without bounds checking. This allows up to 735 bytes of attacker-controlled data to be written past the buffer, potentially corrupting adjacent stack data and control-flow data. The overflow occurs before AES-GCM authentication is verified, meaning the attacker does not need the OAuth key or a valid token. This issue requires the server to be running in --oauth mode. This may provide a remote code execution primitive.
Recommendations Update to version 4.10.0. As a temporary workaround, disable --oauth mode to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43994

Affected Products

Coturn