[Git][security-tracker-team/security-tracker][master] Add new coturn issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 05:46:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
73d86153 by Salvatore Bonaccorso at 2026-08-21T06:40:15+02:00
Add new coturn issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1070,13 +1070,22 @@ CVE-2026-68559 (Wekan is open source kanban built with Meteor. From 9.57 until 9
 CVE-2026-68558 (Wekan is open source kanban built with Meteor. From 8.36 until 9.74, t ...)
 	- wekan <itp> (bug #819238)
 CVE-2026-68555 (Coturn is a free open source implementation of TURN and STUN Server. I ...)
-	TODO: check
+	- coturn <unfixed>
+	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-hpq3-g7x4-h7xx
+	NOTE: Fixed by: https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7 (4.16.0)
 CVE-2026-68554 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	TODO: check
+	- coturn 4.15.0-1
+	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-5538-7cxj-5jcc
+	NOTE: Fixed by: https://github.com/coturn/coturn/commit/ab762f334f511ea37ab4b703a47d5d683a5be978 (4.15.0)
 CVE-2026-68553 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	TODO: check
+	- coturn 4.14.0-1
+	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-4g7c-p5wg-j4hp
+	NOTE: Fixed by: https://github.com/coturn/coturn/commit/8fa38032bb4751e11e072d65a8eca3c06c950979 (4.13.0)
 CVE-2026-68552 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	TODO: check
+	- coturn 4.15.0-1
+	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-m562-mf7x-q7rr
+	NOTE: https://github.com/coturn/coturn/pull/1964
+	NOTE: Fixed by: https://github.com/coturn/coturn/commit/ed32e1fb6c843f9cf9a28d91c541dfbf40874f25 (4.15.0)
 CVE-2026-67189 (pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a store ...)
 	NOT-FOR-US: pfSense Plus
 CVE-2026-63722 (ICEcoder 8.1 contains an unauthenticated remote code execution vulnera ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73d86153b32e3c9dd37e75be24cc14e62cea3778

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/73d86153b32e3c9dd37e75be24cc14e62cea3778
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/bf785552/attachment.htm>


More information about the debian-security-tracker-commits mailing list