CVE-2026-27624 Details
Description
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving "0.0.0.0", "[::1]" and "[::]", but IPv4-mapped IPv6 is not covered. When sending a "CreatePermission" or "ChannelBind" request with the "XOR-PEER-ADDRESS" value of "::ffff:127.0.0.1", a successful response is received, even though "127.0.0.0/8" is blocked via "denied-peer-ip". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in "src/client/ns_turn_ioaddr.c" do not check "IN6_IS_ADDR_V4MAPPED". "ioa_addr_is_loopback()" checks "127.x.x.x" (AF_INET) and "::1" (AF_INET6), but not "::ffff:127.0.0.1." "ioa_addr_is_zero()" checks "0.0.0.0" and "::", but not "::ffff:0.0.0.0." "addr_less_eq()" used by "ioa_addr_in_range()" for "denied-peer-ip" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.
A vulnerability in Coturn's handling of IPv4-mapped IPv6 addresses allows for a bypass of loopback restrictions. Coturn is a free, open-source implementation of TURN and STUN servers, commonly configured to block loopback and internal IP ranges. While previous vulnerabilities were addressed, the handling of IPv4-mapped IPv6 addresses was not properly fixed. This vulnerability affects Coturn versions prior to 4.5.2 and version 4.8.0.
Users should upgrade to Coturn version 4.5.2 or later, and explicitly deny IPv4-mapped addresses in their 'denied-peer-ip' settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p | CISA-ADP | Not Applicable |
| https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg | CISA-ADP | ExploitVendor Advisory |
| https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b | [email protected] | Patch |
| https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p | [email protected] | Not Applicable |
| https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| coturn project coturn | < 4.9.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | New CVE Received | [email protected] |