Unintended Proxy or Intermediary ('Confused Deputy') Affecting coturn/coturn package, versions [,4.9.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-COTURNCOTURN-15364892
  • published28 Feb 2026
  • disclosed25 Feb 2026
  • credittr1xster-sec

Introduced: 25 Feb 2026

CVE-2026-27624  (opens in a new tab)
CWE-441  (opens in a new tab)

How to fix?

Upgrade coturn/coturn to version 4.9.0 or higher.

Overview

Affected versions of this package are vulnerable to Unintended Proxy or Intermediary ('Confused Deputy') in the processing of access control lists for peer IP addresses due to improper handling of IPv4-mapped IPv6 addresses in the ioa_addr_is_loopback, ioa_addr_is_zero, and addr_less_eq functions. An attacker can bypass IP-based access restrictions by submitting requests with specially crafted IPv4-mapped IPv6 addresses.

References

CVSS Base Scores

version 4.0
version 3.1