{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27624",
        "tracking": {
            "current_release_date": "2026-03-23T03:39:49.445285Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27624",
            "initial_release_date": "2026-02-25T05:24:51.129300Z",
            "revision_history": [
                {
                    "date": "2026-02-25T05:24:51.129300Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-25T05:24:55.667341Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-25T05:39:03.514217Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-02-25T05:39:05.782593Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-25T12:42:53.612892Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Products created (2)."
                },
                {
                    "date": "2026-02-25T15:13:46.996004Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-25T15:13:48.959642Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-25T17:22:56.853250Z",
                    "number": "8",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-26T00:12:47.326163Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (64).| Products created (3).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T12:42:54.309250Z",
                    "number": "10",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-02-26T12:43:00.080903Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T18:25:20.550439Z",
                    "number": "12",
                    "summary": "Products created (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-02-27T18:25:22.573974Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:40:28.803349Z",
                    "number": "14",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:40:31.378861Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "15"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.0",
                                "product": {
                                    "name": "vers:unknown/<4.9.0",
                                    "product_id": "CSAFPID-5736014",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:coturn_project:coturn:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "coTURN"
                    }
                ],
                "category": "vendor",
                "name": "coTURN Project"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5702419"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "coturn"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5702420"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "coturn"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.4.5.3",
                                "product": {
                                    "name": "vers:unknown/4.4.5.3",
                                    "product_id": "CSAFPID-4424669"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.4.5.4",
                                "product": {
                                    "name": "vers:unknown/4.4.5.4",
                                    "product_id": "CSAFPID-4424670"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.1",
                                "product": {
                                    "name": "vers:unknown/4.5.0.1",
                                    "product_id": "CSAFPID-4424671"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.2",
                                "product": {
                                    "name": "vers:unknown/4.5.0.2",
                                    "product_id": "CSAFPID-4424672"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.3",
                                "product": {
                                    "name": "vers:unknown/4.5.0.3",
                                    "product_id": "CSAFPID-4424673"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.4",
                                "product": {
                                    "name": "vers:unknown/4.5.0.4",
                                    "product_id": "CSAFPID-4424674"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.5",
                                "product": {
                                    "name": "vers:unknown/4.5.0.5",
                                    "product_id": "CSAFPID-4424675"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.6",
                                "product": {
                                    "name": "vers:unknown/4.5.0.6",
                                    "product_id": "CSAFPID-4424676"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.7",
                                "product": {
                                    "name": "vers:unknown/4.5.0.7",
                                    "product_id": "CSAFPID-4424677"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.0.8",
                                "product": {
                                    "name": "vers:unknown/4.5.0.8",
                                    "product_id": "CSAFPID-4424678"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.1.0",
                                "product": {
                                    "name": "vers:unknown/4.5.1.0",
                                    "product_id": "CSAFPID-4424679"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.1.1",
                                "product": {
                                    "name": "vers:unknown/4.5.1.1",
                                    "product_id": "CSAFPID-4424680"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.1.2",
                                "product": {
                                    "name": "vers:unknown/4.5.1.2",
                                    "product_id": "CSAFPID-4481339"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.1.3",
                                "product": {
                                    "name": "vers:unknown/4.5.1.3",
                                    "product_id": "CSAFPID-4481340"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.5.2",
                                "product": {
                                    "name": "vers:unknown/4.5.2",
                                    "product_id": "CSAFPID-5569442"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.6.0",
                                "product": {
                                    "name": "vers:unknown/4.6.0",
                                    "product_id": "CSAFPID-5656593"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.6.1",
                                "product": {
                                    "name": "vers:unknown/4.6.1",
                                    "product_id": "CSAFPID-5656594"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.6.2",
                                "product": {
                                    "name": "vers:unknown/4.6.2",
                                    "product_id": "CSAFPID-5656595"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.6.3",
                                "product": {
                                    "name": "vers:unknown/4.6.3",
                                    "product_id": "CSAFPID-5312455"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.7.0",
                                "product": {
                                    "name": "vers:unknown/4.7.0",
                                    "product_id": "CSAFPID-5312456"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.8.0",
                                "product": {
                                    "name": "vers:unknown/4.8.0",
                                    "product_id": "CSAFPID-5713300"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.0",
                                "product": {
                                    "name": "vers:unknown/<4.9.0",
                                    "product_id": "CSAFPID-5700902"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r0",
                                    "product_id": "CSAFPID-5656596"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r1",
                                    "product_id": "CSAFPID-5656597"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r10",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r10",
                                    "product_id": "CSAFPID-5656598"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r11",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r11",
                                    "product_id": "CSAFPID-5656599"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r12",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r12",
                                    "product_id": "CSAFPID-5656600"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r13",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r13",
                                    "product_id": "CSAFPID-5656601"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r14",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r14",
                                    "product_id": "CSAFPID-5656602"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r2",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r2",
                                    "product_id": "CSAFPID-5656603"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r3",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r3",
                                    "product_id": "CSAFPID-5656604"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r4",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r4",
                                    "product_id": "CSAFPID-5656605"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r5",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r5",
                                    "product_id": "CSAFPID-5656606"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r6",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r6",
                                    "product_id": "CSAFPID-5656607"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r7",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r7",
                                    "product_id": "CSAFPID-5656608"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r8",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r8",
                                    "product_id": "CSAFPID-5656609"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.5.2-r9",
                                "product": {
                                    "name": "vers:unknown/docker/4.5.2-r9",
                                    "product_id": "CSAFPID-5656610"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.0-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.0-r0",
                                    "product_id": "CSAFPID-5656611"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.0-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.0-r1",
                                    "product_id": "CSAFPID-5656612"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.1-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.1-r0",
                                    "product_id": "CSAFPID-5656613"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.1-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.1-r1",
                                    "product_id": "CSAFPID-5656614"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.1-r2",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.1-r2",
                                    "product_id": "CSAFPID-5656615"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.1-r3",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.1-r3",
                                    "product_id": "CSAFPID-5656616"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r0",
                                    "product_id": "CSAFPID-5656617"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r1",
                                    "product_id": "CSAFPID-5656618"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r10",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r10",
                                    "product_id": "CSAFPID-5312457"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r11",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r11",
                                    "product_id": "CSAFPID-5312458"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r12",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r12",
                                    "product_id": "CSAFPID-5312459"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r13",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r13",
                                    "product_id": "CSAFPID-5312460"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r2",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r2",
                                    "product_id": "CSAFPID-5656619"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r3",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r3",
                                    "product_id": "CSAFPID-5656620"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r4",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r4",
                                    "product_id": "CSAFPID-5656621"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r5",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r5",
                                    "product_id": "CSAFPID-5312461"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r6",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r6",
                                    "product_id": "CSAFPID-5312462"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r7",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r7",
                                    "product_id": "CSAFPID-5312463"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r8",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r8",
                                    "product_id": "CSAFPID-5312464"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.2-r9",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.2-r9",
                                    "product_id": "CSAFPID-5312465"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.3-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.3-r0",
                                    "product_id": "CSAFPID-5312466"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.3-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.3-r1",
                                    "product_id": "CSAFPID-5312467"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.3-r2",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.3-r2",
                                    "product_id": "CSAFPID-5312468"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.6.3-r3",
                                "product": {
                                    "name": "vers:unknown/docker/4.6.3-r3",
                                    "product_id": "CSAFPID-5312469"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.7.0-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.7.0-r0",
                                    "product_id": "CSAFPID-5312470"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.7.0-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.7.0-r1",
                                    "product_id": "CSAFPID-5312471"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.7.0-r2",
                                "product": {
                                    "name": "vers:unknown/docker/4.7.0-r2",
                                    "product_id": "CSAFPID-5312472"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.7.0-r3",
                                "product": {
                                    "name": "vers:unknown/docker/4.7.0-r3",
                                    "product_id": "CSAFPID-5312473"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.7.0-r4",
                                "product": {
                                    "name": "vers:unknown/docker/4.7.0-r4",
                                    "product_id": "CSAFPID-5312474"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.8.0-r0",
                                "product": {
                                    "name": "vers:unknown/docker/4.8.0-r0",
                                    "product_id": "CSAFPID-5713301"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/docker/4.8.0-r1",
                                "product": {
                                    "name": "vers:unknown/docker/4.8.0-r1",
                                    "product_id": "CSAFPID-5713302"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "coturn"
                    }
                ],
                "category": "vendor",
                "name": "coturn"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27624",
            "cwe": {
                "id": "CWE-441",
                "name": "Unintended Proxy or Intermediary ('Confused Deputy')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using \"denied-peer-ip\" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving \"0.0.0.0\", \"[::1]\" and \"[::]\", but IPv4-mapped IPv6 is not covered. When sending a \"CreatePermission\" or \"ChannelBind\" request with the \"XOR-PEER-ADDRESS\" value of \"::ffff:127.0.0.1\", a successful response is received, even though \"127.0.0.0/8\" is blocked via \"denied-peer-ip\". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in \"src/client/ns_turn_ioaddr.c\" do not check \"IN6_IS_ADDR_V4MAPPED\". \"ioa_addr_is_loopback()\" checks \"127.x.x.x\" (AF_INET) and \"::1\" (AF_INET6), but not \"::ffff:127.0.0.1.\" \"ioa_addr_is_zero()\" checks \"0.0.0.0\" and \"::\", but not \"::ffff:0.0.0.0.\" \"addr_less_eq()\" used by \"ioa_addr_in_range()\" for \"denied-peer-ip\" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-27624"
                },
                {
                    "category": "description",
                    "text": "Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using \"denied-peer-ip\" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving \"0.0.0.0\", \"[::1]\" and \"[::]\", but IPv4-mapped IPv6 is not covered. When sending a \"CreatePermission\" or \"ChannelBind\" request with the \"XOR-PEER-ADDRESS\" value of \"::ffff:127.0.0.1\", a successful response is received, even though \"127.0.0.0/8\" is blocked via \"denied-peer-ip\". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in \"src/client/ns_turn_ioaddr.c\" do not check \"IN6_IS_ADDR_V4MAPPED\". \"ioa_addr_is_loopback()\" checks \"127.x.x.x\" (AF_INET) and \"::1\" (AF_INET6), but not \"::ffff:127.0.0.1.\" \"ioa_addr_is_zero()\" checks \"0.0.0.0\" and \"::\", but not \"::ffff:0.0.0.0.\" \"addr_less_eq()\" used by \"ioa_addr_in_range()\" for \"denied-peer-ip\" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-27624"
                },
                {
                    "category": "description",
                    "text": "Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using \"denied-peer-ip\" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving \"0.0.0.0\", \"[::1]\" and \"[::]\", but IPv4-mapped IPv6 is not covered. When sending a \"CreatePermission\" or \"ChannelBind\" request with the \"XOR-PEER-ADDRESS\" value of \"::ffff:127.0.0.1\", a successful response is received, even though \"127.0.0.0/8\" is blocked via \"denied-peer-ip\". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in \"src/client/ns_turn_ioaddr.c\" do not check \"IN6_IS_ADDR_V4MAPPED\". \"ioa_addr_is_loopback()\" checks \"127.x.x.x\" (AF_INET) and \"::1\" (AF_INET6), but not \"::ffff:127.0.0.1.\" \"ioa_addr_is_zero()\" checks \"0.0.0.0\" and \"::\", but not \"::ffff:0.0.0.0.\" \"addr_less_eq()\" used by \"ioa_addr_in_range()\" for \"denied-peer-ip\" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27624.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using \"denied-peer-ip\" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving \"0.0.0.0\", \"[::1]\" and \"[::]\", but IPv4-mapped IPv6 is not covered. When sending a \"CreatePermission\" or \"ChannelBind\" request with the \"XOR-PEER-ADDRESS\" value of \"::ffff:127.0.0.1\", a successful response is received, even though \"127.0.0.0/8\" is blocked via \"denied-peer-ip\". The root cause is that, prior to the updated fix implemented in version 4.9.0, three functions in \"src/client/ns_turn_ioaddr.c\" do not check \"IN6_IS_ADDR_V4MAPPED\". \"ioa_addr_is_loopback()\" checks \"127.x.x.x\" (AF_INET) and \"::1\" (AF_INET6), but not \"::ffff:127.0.0.1.\" \"ioa_addr_is_zero()\" checks \"0.0.0.0\" and \"::\", but not \"::ffff:0.0.0.0.\" \"addr_less_eq()\" used by \"ioa_addr_in_range()\" for \"denied-peer-ip\" matching: when the range is AF_INET and the peer is AF_INET6, the comparison returns 0 without extracting the embedded IPv4. Version 4.9.0 contains an updated fix to address the bypass of the fix for CVE-2020-26262.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-27624"
                },
                {
                    "category": "other",
                    "text": "0.00035",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "3.8",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, There is exploit data available from source Nvd, Exploit code publicly available",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5700902",
                    "CSAFPID-5702419",
                    "CSAFPID-5702420",
                    "CSAFPID-4424669",
                    "CSAFPID-4424670",
                    "CSAFPID-4424671",
                    "CSAFPID-4424672",
                    "CSAFPID-4424673",
                    "CSAFPID-4424674",
                    "CSAFPID-4424675",
                    "CSAFPID-4424676",
                    "CSAFPID-4424677",
                    "CSAFPID-4424678",
                    "CSAFPID-4424679",
                    "CSAFPID-4424680",
                    "CSAFPID-4481339",
                    "CSAFPID-4481340",
                    "CSAFPID-5312455",
                    "CSAFPID-5312456",
                    "CSAFPID-5312457",
                    "CSAFPID-5312458",
                    "CSAFPID-5312459",
                    "CSAFPID-5312460",
                    "CSAFPID-5312461",
                    "CSAFPID-5312462",
                    "CSAFPID-5312463",
                    "CSAFPID-5312464",
                    "CSAFPID-5312465",
                    "CSAFPID-5312466",
                    "CSAFPID-5312467",
                    "CSAFPID-5312468",
                    "CSAFPID-5312469",
                    "CSAFPID-5312470",
                    "CSAFPID-5312471",
                    "CSAFPID-5312472",
                    "CSAFPID-5312473",
                    "CSAFPID-5312474",
                    "CSAFPID-5569442",
                    "CSAFPID-5656593",
                    "CSAFPID-5656594",
                    "CSAFPID-5656595",
                    "CSAFPID-5656596",
                    "CSAFPID-5656597",
                    "CSAFPID-5656598",
                    "CSAFPID-5656599",
                    "CSAFPID-5656600",
                    "CSAFPID-5656601",
                    "CSAFPID-5656602",
                    "CSAFPID-5656603",
                    "CSAFPID-5656604",
                    "CSAFPID-5656605",
                    "CSAFPID-5656606",
                    "CSAFPID-5656607",
                    "CSAFPID-5656608",
                    "CSAFPID-5656609",
                    "CSAFPID-5656610",
                    "CSAFPID-5656611",
                    "CSAFPID-5656612",
                    "CSAFPID-5656613",
                    "CSAFPID-5656614",
                    "CSAFPID-5656615",
                    "CSAFPID-5656616",
                    "CSAFPID-5656617",
                    "CSAFPID-5656618",
                    "CSAFPID-5656619",
                    "CSAFPID-5656620",
                    "CSAFPID-5656621",
                    "CSAFPID-5713300",
                    "CSAFPID-5713301",
                    "CSAFPID-5713302",
                    "CSAFPID-5736014"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27624"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27624"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27624"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27624.json"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-27624"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-27624"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-27624.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/coturn/coturn/commit/b80eb898ba26552600770162c26a8ae7f3661b0b"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/coturn/coturn/security/advisories/GHSA-6g6j-r9rf-cm7p"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/coturn/coturn/security/advisories/GHSA-j8mm-mpf8-gvjg"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27624.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27624"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-4424669",
                        "CSAFPID-4424670",
                        "CSAFPID-4424671",
                        "CSAFPID-4424672",
                        "CSAFPID-4424673",
                        "CSAFPID-4424674",
                        "CSAFPID-4424675",
                        "CSAFPID-4424676",
                        "CSAFPID-4424677",
                        "CSAFPID-4424678",
                        "CSAFPID-4424679",
                        "CSAFPID-4424680",
                        "CSAFPID-4481339",
                        "CSAFPID-4481340",
                        "CSAFPID-5312455",
                        "CSAFPID-5312456",
                        "CSAFPID-5312457",
                        "CSAFPID-5312458",
                        "CSAFPID-5312459",
                        "CSAFPID-5312460",
                        "CSAFPID-5312461",
                        "CSAFPID-5312462",
                        "CSAFPID-5312463",
                        "CSAFPID-5312464",
                        "CSAFPID-5312465",
                        "CSAFPID-5312466",
                        "CSAFPID-5312467",
                        "CSAFPID-5312468",
                        "CSAFPID-5312469",
                        "CSAFPID-5312470",
                        "CSAFPID-5312471",
                        "CSAFPID-5312472",
                        "CSAFPID-5312473",
                        "CSAFPID-5312474",
                        "CSAFPID-5569442",
                        "CSAFPID-5656593",
                        "CSAFPID-5656594",
                        "CSAFPID-5656595",
                        "CSAFPID-5656596",
                        "CSAFPID-5656597",
                        "CSAFPID-5656598",
                        "CSAFPID-5656599",
                        "CSAFPID-5656600",
                        "CSAFPID-5656601",
                        "CSAFPID-5656602",
                        "CSAFPID-5656603",
                        "CSAFPID-5656604",
                        "CSAFPID-5656605",
                        "CSAFPID-5656606",
                        "CSAFPID-5656607",
                        "CSAFPID-5656608",
                        "CSAFPID-5656609",
                        "CSAFPID-5656610",
                        "CSAFPID-5656611",
                        "CSAFPID-5656612",
                        "CSAFPID-5656613",
                        "CSAFPID-5656614",
                        "CSAFPID-5656615",
                        "CSAFPID-5656616",
                        "CSAFPID-5656617",
                        "CSAFPID-5656618",
                        "CSAFPID-5656619",
                        "CSAFPID-5656620",
                        "CSAFPID-5656621",
                        "CSAFPID-5700902",
                        "CSAFPID-5702419",
                        "CSAFPID-5702420",
                        "CSAFPID-5713300",
                        "CSAFPID-5713301",
                        "CSAFPID-5713302",
                        "CSAFPID-5736014"
                    ]
                }
            ],
            "title": "CVE-2026-27624"
        }
    ]
}