LOWVulnerability
CVE-2026-73214
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0.
Properties
- epss_score
- 0.00423
- cve_id
- CVE-2026-73214
- published_at
- 2026-08-11T18:18:26.773
- last_modified
- 2026-09-09T20:55:04.493
- epss_percentile
- 0.35665
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (2)
→[Weakness]Allocation of Resources Without Limits or Throttling
→[Weakness]Uncontrolled Resource Consumption
Explore deeper with Ninja Signal's threat intelligence graph