Back Linuxsecurity Fedora 44 Coturn 4.13.1 Security Fix Cross
Coturn 4.13.1 What's in this release Security fixes What's Changed Null-terminate server_name in stun_is_challenge_response_str Canonicalize all IPv4-in-IPv6 encodings before peer-IP checks Auto-deny coturn's own database backend endpoints as relay peers Deny link-local / ULA / site-local relay peers by default Coturn 4.13.0 What's in this release More performance improvements for --udp-recvmmsg and --multiplex-peer. If your system does not rely on TURN unique ports give multiplexing a try - it has capacity to dramatically increase performance. Security fixes What's Changed Wrap atomic everywhere Fix sendmmsg stride bug in multiplex-peer UDP batch flush Reap TURN permissions/channels via a per-thread sweep instead of per-object timers Add --udp-sendmmsg-log to observe egress sendmmsg/UDP-GSO batching Expose recvmmsg/sendmmsg UDP batch sizes as Prometheus metrics Restrict recvmmsg fast path to shared fan-in sockets (make --udp-recvmmsg useful standalone) Enable...
* Tue Jun 16 2026 Robert Scheck - 4.13.1-1 - Upgrade to 4.13.1 (#2488712 #c1) * Sun Jun 14 2026 Robert Scheck - 4.13.0-1 - Upgrade to 4.13.0 (#2488712) * Fri Jun 12 2026 Yaakov Selkowitz - 4.12.0-3 - Rebuilt for openssl 4.0
* Tue Jun 16 2026 Robert Scheck - 4.13.1-1 - Upgrade to 4.13.1 (#2488712 #c1) * Sun Jun 14 2026 Robert Scheck - 4.13.0-1 - Upgrade to 4.13.0 (#2488712) * Fri Jun 12 2026 Yaakov Selkowitz - 4.12.0-3 - Rebuilt for openssl 4.0
[ 1 ] Bug #2490558 - CVE-2026-43915 coturn: Coturn: Cross-Site Scripting (XSS) via crafted username in TURN allocation
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dda1360c18' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
