What is CVE-2026-62959?
A vulnerability in the Coturn TURN/STUN server affects versions 4.5.2 through 4.14.0. If the server is started with the `--acme-redirect <URL>` flag and exposes a plaintext-TCP listener, an unauthenticated remote client can send a specific HTTP GET request and receive a 301 redirect response. It is recommended to update Coturn to the latest version to patch this flaw.
Azərbaycanca: Coturn TURN/STUN server-in 4.5.2-dən 4.14.0-a qədər versiyalarında zəiflikdir. Əgər server `--acme-redirect <URL>` flagi ilə işə salınıbsa və plaintext-TCP listener aktivdirsə, autentifikasiya olunmamış uzaq bir müştəri xüsusi HTTP GET sorğusu göndərərək 301 yönləndirmə cavabı ala bilər. Bu zəifliyi aradan qaldırmaq üçün Coturn-u ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the Coturn server are affected by CVE-2026-62959?
This vulnerability affects Coturn versions 4.5.2 through 4.14.0.
How must the server be configured for CVE-2026-62959 to be exploited?
For this vulnerability to be exploited, the server must be started with the `--acme-redirect <URL>` flag and a plaintext-TCP listener must be active.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.