{"id":"CVE-2026-104074","summary":"Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE","details":"Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by sending a TURN Allocate request without credentials. Attackers can exploit the stun_init_error_response_common_str() function in src/client/ns_turn_msg.c, which fails to zero-initialize the avalue buffer before computing its length with strlen() and copying leaked stack bytes into the ERROR-CODE reason phrase, exposing pointer fragments that weaken ASLR and enable precise version fingerprinting.","modified":"2026-10-08T10:30:39.192181709Z","published":"2026-10-07T14:29:45.615Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-908"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104074.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104074.json"},{"type":"PACKAGE","url":"https://github.com/coturn/coturn"},{"type":"FIX","url":"https://github.com/coturn/coturn/commit/741b2983cc52f967dd08c438fd72a5f08f13ca27"},{"type":"REPORT","url":"https://github.com/coturn/coturn/pull/1878"},{"type":"ADVISORY","url":"https://github.com/coturn/coturn/releases/tag/4.11.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104074"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coturn/coturn","events":[{"introduced":"8e2c575229de615a3414bd9c81215c3b040471b4"},{"fixed":"97fd597fcb64861392b399ac824b044a2f0f5786"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"4.10.0"},{"fixed":"4.11.0"}]}}],"versions":["docker/4.10.0-r1","docker/4.10.0-r0","4.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104074.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}