{"id":"CVE-2026-27624","summary":"Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL","details":"Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using \"denied-peer-ip\" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving \"0.0.0.0\", \"[::1]\" and \"[::]\", but IPv4-mapped IPv6 is not covered. When sending a \"CreatePermission\" or \"ChannelBind\" request with the \"XOR-PEER-ADDRESS\" value of \"::ffff:127.0.0.1\", a successful response is received, even though \"127.0.0.0/8\" is blocked via \"denied-peer-ip\". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in \"src/client/ns_turn_ioaddr.c\" do not check \"IN6_IS_ADDR_V4MAPPED\". \"ioa_addr_is_loopback()\" checks \"127.x.x.x\" (AF_INET) and \"::1\" (AF_INET6), but not \"::ffff:127.0.0.1.\" \"ioa_addr_is_zero()\" checks \"0.0.0.0\" and \"::\", but not \"::ffff:0.0.0.0.\" \"addr_less_eq()\" used by \"ioa_addr_in_range()\" for \"denied-peer-ip\" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.","modified":"2026-08-12T15:32:07.462116Z","published":"2026-02-25T04:04:17.009Z","related":["GHSA-6g6j-r9rf-cm7p","GHSA-j8mm-mpf8-gvjg","openSUSE-SU-2026:10375-1","openSUSE-SU-2026:21184-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284","CWE-441"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27624.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27624.json"},{"type":"ADVISORY","url":"https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p"},{"type":"ADVISORY","url":"https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27624"},{"type":"FIX","url":"https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coturn/coturn","events":[{"introduced":"0"},{"fixed":"41ba6d8f5d073ab27440ef061022eb88123fba62"},{"fixed":"b80eb898ba26552600770162c26a8ae7f3661b0b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.9.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:coturn_project:coturn:*:*:*:*:*:*:*:*"}}],"versions":["docker/4.8.0-r1","docker/4.8.0-r0","4.8.0","docker/4.7.0-r4","docker/4.7.0-r3","docker/4.7.0-r2","docker/4.7.0-r1","docker/4.7.0-r0","4.7.0","docker/4.6.3-r3","docker/4.6.3-r2","docker/4.6.3-r1","docker/4.6.3-r0","4.6.3","docker/4.6.2-r13","docker/4.6.2-r12","docker/4.6.2-r11","docker/4.6.2-r10","docker/4.6.2-r9","docker/4.6.2-r8","docker/4.6.2-r7","docker/4.6.2-r6","docker/4.6.2-r5","docker/4.6.2-r4","docker/4.6.2-r3","docker/4.6.2-r2","docker/4.6.2-r1","docker/4.6.2-r0","4.6.2","docker/4.6.1-r3","docker/4.6.1-r2","docker/4.6.1-r1","docker/4.6.1-r0","docker/4.6.0-r1","docker/4.6.0-r0","4.6.0","docker/4.5.2-r14","docker/4.5.2-r13","docker/4.5.2-r12","docker/4.5.2-r11","docker/4.5.2-r10","docker/4.5.2-r9","docker/4.5.2-r8","docker/4.5.2-r7","docker/4.5.2-r6","docker/4.5.2-r0","4.5.2","4.5.1.3","4.5.1.2","4.5.1.1","4.5.1.0","4.5.0.7","4.5.0.6","4.5.0.5","4.5.0.4","4.5.0.3","4.5.0.2","4.5.0.1","4.4.5.4","4.4.5.3"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:32:07Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b","target":{"file":"src/client/ns_turn_ioaddr.c","function":"ioa_addr_is_multicast"},"deprecated":false,"digest":{"function_hash":"55511574181879640123181948780952487320","length":366},"id":"CVE-2026-27624-2a5ae020","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b","target":{"file":"src/client/ns_turn_ioaddr.c"},"deprecated":false,"digest":{"line_hashes":["93328447809025428638579479010601090610","160850680920347367599919116943064515135","327249086968038752494120765449810280968","166675379164985798946415014504370539289","100961205862538373677842976129490923751","92284864913154121649803361604799215329","134736082074896808494834923880729564990","90183373891725346072700539711373910532","139477924430625930175683012285651675924","129845873133191568953762808756726623819","40098721692768284248455193710218853797","243755226202521114884883129314620457132","40192689717957874238783082126931959055","99451377433655794018633471570645083470","31791693889040752621205924480325901461","315897395042224313616601671324713415412","245119364497097473818140195523542244913"],"threshold":0.9},"id":"CVE-2026-27624-90b1da71"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b","target":{"file":"src/client/ns_turn_ioaddr.c","function":"ioa_addr_is_loopback"},"deprecated":false,"digest":{"function_hash":"61522260528341883777217419680737068841","length":463},"id":"CVE-2026-27624-c077774c"},{"id":"CVE-2026-27624-c9035197","signature_type":"Function","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b","target":{"file":"src/client/ns_turn_ioaddr.c","function":"ioa_addr_is_zero"},"deprecated":false,"digest":{"function_hash":"30778363800214886557045114808947156380","length":435}},{"target":{"file":"src/client/ns_turn_ioaddr.c","function":"ioa_addr_in_range"},"deprecated":false,"digest":{"function_hash":"130213156042472298931457621488322771162","length":299},"id":"CVE-2026-27624-d3cc92bd","signature_type":"Function","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27624.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}