Impact
An authenticated client can send Allocate requests with the even-port flag set and reservation bit R=0 to cause coturn to incorrectly mark an unused odd sibling port as taken. This prevents the port from ever being released, leading to exhaustion of the relay port pool and subsequent allocation attempts failing with STUN error 508. The weakness is an uncontrolled resource consumption and missing resource release flaw, as reflected by CWE-400 and CWE-772. The resulting denial of service can affect any TURN user relying on this server for relaying media streams.
Affected Systems
The vulnerability is present in all coturn releases prior to version 4.17.0. Users running coturn versions 4.16.x and below, regardless of operating system, are vulnerable. The issue was addressed in the 4.17.0 release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The current EPSS score of less than 1% shows that the likelihood of exploitation is low, and the vulnerability is not listed in CISA KEV. The attack vector requires a valid authenticated client that can send STUN Allocate requests with the even-port flag; therefore it is not an open surface attack but can be leveraged by any trusted user to sink the server’s port resources.
OpenCVE Enrichment