• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

processone / stun / 111
52%
master: 52%

Build:
Build:
LAST BUILD BRANCH: HEAD
DEFAULT BRANCH: master
Ran 11 Aug 2026 01:01PM UTC
Jobs 1
Files 15
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

11 Aug 2026 12:58PM UTC coverage: 56.656% (+1.3%) from 55.359%
111

push

github

jsautret
Fix TURN nonce reuse from different source addresses

Bind TURN nonces to the client's source address to prevent nonce reuse
attacks. Previously, an attacker could obtain a valid nonce from their
own IP address and reuse it in requests sent from a different (potentially
spoofed) source address, enabling creation of spoofed TURN allocations.

This vulnerability has existed since TURN support was first added in
version 0.9.0 (May 2014).

Severity: Medium (CVSS 3.1: 5.9)
CWE-287: Improper Authentication
CWE-346: Origin Validation Error

Thanks to Christoph Sanders for reporting the issue.

18 of 18 new or added lines in 2 files covered. (100.0%)

681 of 1202 relevant lines covered (56.66%)

2.88 hits per line

Jobs
ID Job ID Ran Files Coverage
1 111.1 11 Aug 2026 01:01PM UTC 15
56.66
GitHub Action Run
Source Files on build 111
  • Tree
  • List 15
  • Changed 4
  • Source Changed 2
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 11775d99 on github
  • Prev Build on (#110)
  • Next Build on (#112)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc