<Vulnerability name="CVE-2026-68553">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-19T20:37:42</PublicDate>
    <Bugzilla id="2520746" url="https://bugzilla.redhat.com/show_bug.cgi?id=2520746" xml:lang="en:us">
coturn: Coturn: Format string vulnerability leads to denial of service and information disclosure
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-134</CWE>
    <Details xml:lang="en:us" source="Mitre">
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Coturn. An authenticated TURN user can exploit a format string vulnerability by injecting printf-style format specifiers into the STUN USERNAME or REALM attribute. This can lead to a crash of the coturn process, resulting in a Denial of Service (DoS) and termination of active TURN sessions. Additionally, this vulnerability may disclose sensitive stack memory into Redis.
    </Details>
    <Statement xml:lang="en:us">
Coturn is not shipped in any Red Hat product. The Fedora and EPEL community builds ship coturn version 4.17.2, which already includes the fix for this issue (fixed in 4.13.0) and are therefore not affected.
    </Statement>
    <Mitigation xml:lang="en:us">
Upgrade to coturn version 4.13.0 or later.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-68553
https://nvd.nist.gov/vuln/detail/CVE-2026-68553
https://github.com/coturn/coturn/commit/8fa38032bb4751e11e072d65a8eca3c06c950979
https://github.com/coturn/coturn/releases/tag/4.13.0
https://github.com/coturn/coturn/security/advisories/GHSA-4g7c-p5wg-j4hp
    </References>
</Vulnerability>