{"apiVersion":"1.0","identifier":"CVE-2026-68552","description":"Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() in src/client/ns_turn_msg.c to wrap when STUN_HEADER_LENGTH is added. The framing layer then consumes only 4 through 16 bytes, treats the remaining bytes as another message, desynchronizes the stream parser, and drops the attacking client-s connection. Other clients and the server process are not affected. This issue is fixed in version 4.15.0.","publishedAt":"2026-08-19T21:17:28","lastModifiedAt":"2026-08-21T22:16:43","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68552","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","epssProbability":0.00315,"riskScore":0.55,"affectedProduct":"coturn","affectedVersions":"<4.15.0","vulnerabilityType":"Critical software","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-68552","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-68552","en":"https://www.redsauce.net/en/cves/CVE-2026-68552","fr":"https://www.redsauce.net/fr/cves/CVE-2026-68552","pt":"https://www.redsauce.net/pt/cves/CVE-2026-68552","de":"https://www.redsauce.net/de/cves/CVE-2026-68552","sk":"https://www.redsauce.net/sk/cves/CVE-2026-68552","el":"https://www.redsauce.net/el/cves/CVE-2026-68552"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-68552"}}