Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting. | |
| Title | Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE | |
| Weaknesses | CWE-908 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T14:29:45.615Z
Reserved: 2026-10-01T18:02:50.083Z
Link: CVE-2026-104074
No data.
Status : Deferred
Published: 2026-10-07T15:17:02.760
Modified: 2026-10-07T15:17:05.537
Link: CVE-2026-104074
No data.
OpenCVE Enrichment
No data.
-
CWE-908
Use of Uninitialized Resource