{"apiVersion":"1.0","identifier":"CVE-2026-68555","description":"Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables --mobility. mobile_begin_transition() in src/server/ns_turn_server.c disarms each new session-s allocation timeout and overwrites the allocation-s single mobile_pending_resume link, leaving earlier pending sessions unreachable by the cleanup path, while copy_auth_parameters() ignores inc_quota() failure. The attacker can therefore retain unbounded server-side sessions and exhaust process memory even when --user-quota=1 is configured. This issue is fixed in version 4.16.0.","publishedAt":"2026-08-19T21:17:28","lastModifiedAt":"2026-08-21T19:17:43","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-68555","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00309,"riskScore":0.67,"affectedProduct":"coturn","affectedVersions":"<4.16.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-68555","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-68555","en":"https://www.redsauce.net/en/cves/CVE-2026-68555","fr":"https://www.redsauce.net/fr/cves/CVE-2026-68555","pt":"https://www.redsauce.net/pt/cves/CVE-2026-68555","de":"https://www.redsauce.net/de/cves/CVE-2026-68555","sk":"https://www.redsauce.net/sk/cves/CVE-2026-68555","el":"https://www.redsauce.net/el/cves/CVE-2026-68555"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-68555"}}