An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.
Conclusion & alert: CVE-2018-4056 is rated High Exploit Risk (76.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.49%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.62% | 0.49% | -0.13% |
| 2 | 2026-03-01 | 0.49% | 0.62% | +0.13% |
| 3 | 2026-02-04 | — | 0.49% | — |
Full EPSS history (40 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.1 | 3.0 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2018-4056 not yet assigned priority: Debian including 1 source packages (coturn), 4 status rows across 4 suites (bookworm, bullseye, sid, trixie): resolved 4. | https://security-tracker.debian.org/tracker/CVE-2018-4056 |
ubuntu
|
medium | CVE-2018-4056 medium priority: Ubuntu including 1 source packages (coturn), 8 status rows across 8 suites (bionic, cosmic, disco, eoan, focal, trusty, upstream, xenial): released 4, not-affected 3, DNE 1. | https://ubuntu.com/security/CVE-2018-4056 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| coturn_project | coturn | < 4.5.0.9 | cpe:2.3:a:coturn_project:coturn:*:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.debian.org/debian-lts-announce/2019/02/msg00017.html | Mailing List Third Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2018-0730 | Exploit Third Party Advisory |
| https://www.debian.org/security/2019/dsa-4373 | Third Party Advisory |