{"id":"CVE-2026-68555","summary":"coturn: Chained mobility resumes allow authenticated remote memory exhaustion","details":"Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables --mobility. mobile_begin_transition() in src/server/ns_turn_server.c disarms each new session's allocation timeout and overwrites the allocation's single mobile_pending_resume link, leaving earlier pending sessions unreachable by the cleanup path, while copy_auth_parameters() ignores inc_quota() failure. The attacker can therefore retain unbounded server-side sessions and exhaust process memory even when --user-quota=1 is configured. This issue is fixed in version 4.16.0.","aliases":["GHSA-hpq3-g7x4-h7xx"],"modified":"2026-08-24T03:59:13.760566Z","published":"2026-08-19T20:43:11.038Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68555.json"},"references":[{"type":"WEB","url":"https://github.com/coturn/coturn/releases/tag/4.16.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68555.json"},{"type":"ADVISORY","url":"https://github.com/coturn/coturn/security/advisories/GHSA-hpq3-g7x4-h7xx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68555"},{"type":"FIX","url":"https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coturn/coturn","events":[{"introduced":"ac6a9633b16a1a35ab248570484e52d138515ad5"},{"fixed":"a97f1924bb435bec49d6d91ae01fa2487c2e1bf7"},{"fixed":"ef409b4227ca16bdd23b3e3eba38530292c20773"}],"database_specific":{"extracted_events":[{"introduced":"4.15.0"},{"fixed":"4.16.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["docker/4.15.0-r0","4.15.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68555.json","vanir_signatures_modified":"2026-08-24T03:59:13Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7","target":{"file":"src/server/ns_turn_server.c"},"deprecated":false,"digest":{"line_hashes":["285780096000608524925583591819894967453","257866803907484564322046499360894445418","172325211774363538844369709538086636071","306089394660509967129159506568368881775","118200179504593419113982426846927778535","93038128435272092038558770458404658311","107028449591125052427403405072485856789","250877749153498772034548367697040819571","218850008885712839738166984666950505823","106366342545371697964771268214662057417","150943477050566740934750505390703323890","283137169894645894788698451859187177047","95956112057415489684451693045247569946","278934002121806830853208103947047643261","23448790390476441114100784794046557628","280959110616112798477413539962234272724","25471816272812963454208665919206892761","60519841684302987534050225415305807050","59463834287174470691515705807122314874"],"threshold":0.9},"id":"CVE-2026-68555-52fa5aa2","signature_type":"Line"},{"target":{"file":"src/server/ns_turn_server.c","function":"mobile_abort_transition"},"deprecated":false,"digest":{"length":330,"function_hash":"47953877983520181555019076378548857990"},"id":"CVE-2026-68555-5a9e0f6f","signature_type":"Function","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7"},{"deprecated":false,"digest":{"function_hash":"150457537054678013249195234482315103309","length":547},"id":"CVE-2026-68555-90fbf7f1","signature_type":"Function","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7","target":{"file":"src/server/ns_turn_server.c","function":"mobile_begin_transition"}},{"digest":{"function_hash":"213723254600753328997983386595947787597","length":726},"id":"CVE-2026-68555-f14081fa","signature_type":"Function","signature_version":"v1","source":"https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7","target":{"function":"mobile_complete_transition","file":"src/server/ns_turn_server.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}