cvedb.io
CVE-2026-43915
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2026-06-18T20:16:13.287 · Last modified 2026-06-26T02:35:52.680

Summary

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the web-admin HTTPS interface. An attacker who can create a TURN allocation with a crafted USERNAME value can inject HTML/JavaScript that executes when an authenticated web-admin user views the TURN session list. In configurations using anonymous TURN access (--no-auth), this may be exploitable without TURN credentials. In authenticated deployments, exploitation requires valid TURN credentials or control over a provisioned username. This issue has been fixed in version 4.11.0.

Affected products

coturn_project — coturn

Does this affect you?

Add your gear to cvedb and we'll alert you only when coturn_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.