Skip to content
Critical XSS Vulnerability in Coturn Affects Fedora 43 and 44

Critical XSS Vulnerability in Coturn Affects Fedora 43 and 44

First seen 24 Jun 2026, 06:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 25, 2026 at 05:38 UTC
  • •CVE-2026-43915 is a critical XSS vulnerability affecting Coturn on Fedora 43 and 44.
  • •The vulnerability allows exploitation via crafted usernames in TURN allocations.
  • •Users are advised to upgrade to Coturn 4.13.1 to mitigate risks.

A critical Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-43915 affects Coturn versions 4.13.1 and 4.13.0 on Fedora 43 and 44. The vulnerability allows attackers to exploit crafted usernames in TURN allocations, potentially compromising user data. Users of Fedora 43 and 44 are urged to upgrade to the patched version to mitigate the risk. The vulnerability was publicly disclosed on June 18, 2026, and is considered critical due to its potential impact on users relying on TURN services. The updates include security fixes and performance improvements. Administrators can apply the updates using the 'dnf' command. The vulnerability is particularly concerning for organizations using Coturn for real-time communications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 98d ago How this analysis works

Timeline

2026-06-18
CVE-2026-43915 published
CVE-2026-43915 disclosed, detailing a critical XSS vulnerability in Coturn affecting Fedora systems.
Linuxsecurity
2026-06-24
Security advisory issued for Fedora 43 and 44
Fedora users are urged to upgrade to Coturn 4.13.1 to address the critical XSS vulnerability.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-43915 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed