LOWVulnerability

CVE-2026-73214

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0.

Properties

epss_score
0.00423
cve_id
CVE-2026-73214
published_at
2026-08-11T18:18:26.773
last_modified
2026-09-09T20:55:04.493
epss_percentile
0.35665

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Allocation of Resources Without Limits or Throttling
[Weakness]Uncontrolled Resource Consumption

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73214 — Ninja Signal Threat Intelligence | Ninja Signal