cursed #4

Closed
forgejo wants to merge 2 commits from refs/pull/4/head into main
forgejo commented 2026-05-14 21:01:06 +00:00 (Migrated from git.smallhack.org)

This PR contains the following updates:

Package Update Change
coturn/coturn minor 4.8.0 → 4.11.0

⚠️ Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

coturn/coturn (coturn/coturn)

v4.11.0

Compare Source

In this release

What's Changed

Full Changelog: https://github.com/coturn/coturn/compare/4.10.0...4.11.0

v4.10.0

Compare Source

  • Performance

    • Add Linux-only recvmmsg client receive path for DTLS/UDP listener (#​1852)
    • Skip response buffer allocation for STUN indications
    • Remove mutex from per-thread super_memory allocator (#​1851)
    • Eliminate mutex and reduce copies on auth message dispatch (#​1843)
    • Replace mutex_bps with lock-free atomics for bandwidth tracking (#​1846)
    • Remove unused mutex from ur_map structure (#​1861)
    • WebRTC Auth optimization path (#​1860)
    • Improve worst case scenario - avoid memory allocation (#​1823)
  • Memory issues

    • Fix null pointer dereferences in post_parse() (#​1859)
    • Fix stack buffer overflow in OAuth token decoding (#​1850)
    • Fix uint16_t truncation overflow in stun_get_message_len_str() (#​1844)
    • Initialize variables before use (#​1832)
  • Security

    • CVE-2026-40613 Misaligned Memory Access STUN Attribute Parser
  • General Improvements

    • Disable reason string in response messages to reduce amplification factor (#​1829)
    • Keep only NEV_UDP_SOCKET_PER_THREAD network engine (#​1849)
    • Replace perror with logging (#​1831)
    • Extend seed corpus (#​1858) and add more fuzzing scenarios (#​1857)
    • Update config and Readme files about deprecated TLSv1/1.1 (#​1848)
    • Restore RFC 3489 (old STUN) backward compatibility broken since 4.7.0 (#​1839)
    • Change port identifiers to use uint16_t (#​1752)
    • Fixes: run_tests.sh and no db (#​1834)
    • Improve PostgreSQL.md Clarity (#​1833)
    • Add session usage reporting callback to TURN database driver (#​1794)
    • CLI interface is disabled by default (#​1830

v4.9.0

Compare Source

  • Multiple security fixes
  • Fix to Web Admin password check
  • Cleanup of deprecated openssl APIs
  • Fix for CVE-2026-27624: bypass localhost and IP range block using IPv4-mapped IPv6

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [coturn/coturn](https://github.com/coturn/coturn) | minor | `4.8.0` → `4.11.0` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the warning logs for more information. --- ### Release Notes <details> <summary>coturn/coturn (coturn/coturn)</summary> ### [`v4.11.0`](https://github.com/coturn/coturn/releases/tag/4.11.0) [Compare Source](https://github.com/coturn/coturn/compare/4.10.0...4.11.0) #### In this release - Unit tests! - Multiple performance improvements - Multiple security fixes - Increased fuzzing coverage <https://introspector.oss-fuzz.com/project-profile?project=coturn> - Additional memory validation using fil-c compiler #### What's Changed - Fix prometheus response memory leak introduced in 4.10.0 - Use constant-time compare for STUN MESSAGE-INTEGRITY HMAC by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1869](https://github.com/coturn/coturn/pull/1869) - Fix format-string injection in Redis DB driver by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1870](https://github.com/coturn/coturn/pull/1870) - Abort on malformed allowed/denied-peer-ip at startup by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1872](https://github.com/coturn/coturn/pull/1872) - Pin session origin only after MESSAGE-INTEGRITY validates by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1871](https://github.com/coturn/coturn/pull/1871) - Fix build failure: define \_GNU\_SOURCE for recvmmsg() on Linux by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1868](https://github.com/coturn/coturn/pull/1868) - Drop udp\_relay\_servers\_number config and clean up dead UDP id-space by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1874](https://github.com/coturn/coturn/pull/1874) - Add Unity-based unit test scaffolding by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1875](https://github.com/coturn/coturn/pull/1875) - Delete log line per relay thread on start by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1876](https://github.com/coturn/coturn/pull/1876) - Out of bound HTTP detection in parser by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1877](https://github.com/coturn/coturn/pull/1877) - Extend STUN client fuzz builder coverage by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1878](https://github.com/coturn/coturn/pull/1878) - Extend fuzzing coverage and enable local fuzzing in a container by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1881](https://github.com/coturn/coturn/pull/1881) - Cover all public stun\_buffer.c wrappers in FuzzStunClient by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1883](https://github.com/coturn/coturn/pull/1883) - HTTP parsing fixes by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1882](https://github.com/coturn/coturn/pull/1882) - Unblock fuzz coverage for is\_http and rare STUN attributes by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1884](https://github.com/coturn/coturn/pull/1884) - Seed address-mapping table in fuzz initializer by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1885](https://github.com/coturn/coturn/pull/1885) - Add deterministic challenge-response builder to FuzzStun by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1886](https://github.com/coturn/coturn/pull/1886) - Add fuzz coverage for integrity helpers by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1888](https://github.com/coturn/coturn/pull/1888) - Hoist turn\_server\_get\_engine() out of per-packet hot path by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1889](https://github.com/coturn/coturn/pull/1889) - Inline addr\_cpy() in the header by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1892](https://github.com/coturn/coturn/pull/1892) - Trim two redundant checks from per-packet relay hot path by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1890](https://github.com/coturn/coturn/pull/1890) - Inline get\_ioa\_addr\_len() in the header by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1891](https://github.com/coturn/coturn/pull/1891) - Cache hot lookups in TURN data-path handlers by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1893](https://github.com/coturn/coturn/pull/1893) - Load generator mode in turnutils\_uclient by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1894](https://github.com/coturn/coturn/pull/1894) - Filc harness and pointer typedefs by [@&#8203;eakraly](https://github.com/eakraly) in [#&#8203;1896](https://github.com/coturn/coturn/pull/1896) **Full Changelog**: <https://github.com/coturn/coturn/compare/4.10.0...4.11.0> ### [`v4.10.0`](https://github.com/coturn/coturn/releases/tag/4.10.0) [Compare Source](https://github.com/coturn/coturn/compare/4.9.0...4.10.0) - Performance - Add Linux-only recvmmsg client receive path for DTLS/UDP listener ([#&#8203;1852](https://github.com/coturn/coturn/issues/1852)) - Skip response buffer allocation for STUN indications - Remove mutex from per-thread super\_memory allocator ([#&#8203;1851](https://github.com/coturn/coturn/issues/1851)) - Eliminate mutex and reduce copies on auth message dispatch ([#&#8203;1843](https://github.com/coturn/coturn/issues/1843)) - Replace mutex\_bps with lock-free atomics for bandwidth tracking ([#&#8203;1846](https://github.com/coturn/coturn/issues/1846)) - Remove unused mutex from ur\_map structure ([#&#8203;1861](https://github.com/coturn/coturn/issues/1861)) - WebRTC Auth optimization path ([#&#8203;1860](https://github.com/coturn/coturn/issues/1860)) - Improve worst case scenario - avoid memory allocation ([#&#8203;1823](https://github.com/coturn/coturn/issues/1823)) - Memory issues - Fix null pointer dereferences in post\_parse() ([#&#8203;1859](https://github.com/coturn/coturn/issues/1859)) - Fix stack buffer overflow in OAuth token decoding ([#&#8203;1850](https://github.com/coturn/coturn/issues/1850)) - Fix uint16\_t truncation overflow in stun\_get\_message\_len\_str() ([#&#8203;1844](https://github.com/coturn/coturn/issues/1844)) - Initialize variables before use ([#&#8203;1832](https://github.com/coturn/coturn/issues/1832)) - Security - CVE-2026-40613 Misaligned Memory Access STUN Attribute Parser - General Improvements - Disable reason string in response messages to reduce amplification factor ([#&#8203;1829](https://github.com/coturn/coturn/issues/1829)) - Keep only NEV\_UDP\_SOCKET\_PER\_THREAD network engine ([#&#8203;1849](https://github.com/coturn/coturn/issues/1849)) - Replace perror with logging ([#&#8203;1831](https://github.com/coturn/coturn/issues/1831)) - Extend seed corpus ([#&#8203;1858](https://github.com/coturn/coturn/issues/1858)) and add more fuzzing scenarios ([#&#8203;1857](https://github.com/coturn/coturn/issues/1857)) - Update config and Readme files about deprecated TLSv1/1.1 ([#&#8203;1848](https://github.com/coturn/coturn/issues/1848)) - Restore RFC 3489 (old STUN) backward compatibility broken since 4.7.0 ([#&#8203;1839](https://github.com/coturn/coturn/issues/1839)) - Change port identifiers to use uint16\_t ([#&#8203;1752](https://github.com/coturn/coturn/issues/1752)) - Fixes: run\_tests.sh and no db ([#&#8203;1834](https://github.com/coturn/coturn/issues/1834)) - Improve PostgreSQL.md Clarity ([#&#8203;1833](https://github.com/coturn/coturn/issues/1833)) - Add session usage reporting callback to TURN database driver ([#&#8203;1794](https://github.com/coturn/coturn/issues/1794)) - CLI interface is disabled by default ([#&#8203;1830](https://github.com/coturn/coturn/issues/1830) ### [`v4.9.0`](https://github.com/coturn/coturn/releases/tag/4.9.0) [Compare Source](https://github.com/coturn/coturn/compare/4.8.0...4.9.0) - Multiple security fixes - Fix to Web Admin password check - Cleanup of deprecated openssl APIs - Fix for CVE-2026-27624: bypass localhost and IP range block using IPv4-mapped IPv6 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNjAuNiIsInVwZGF0ZWRJblZlciI6IjQzLjE2MC42IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
forgejo commented 2026-05-14 21:01:06 +00:00 (Migrated from git.smallhack.org)

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: charts/coturn/Chart.yaml
Post-upgrade command 'bash scripts/bump-chart-version.sh 'coturn' 'minor'' has not been added to the allowed list in allowedCommands
### ⚠️ Artifact update problem Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens: - any of the package files in this branch needs updating, or - the branch becomes conflicted, or - you click the rebase/retry checkbox if found above, or - you rename this PR's title to start with "rebase!" to trigger it manually The artifact failure details are included below: ##### File name: charts/coturn/Chart.yaml ``` Post-upgrade command 'bash scripts/bump-chart-version.sh 'coturn' 'minor'' has not been added to the allowed list in allowedCommands ```
forgejo commented 2026-05-14 21:44:04 +00:00 (Migrated from git.smallhack.org)

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

### Edited/Blocked Notification Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. ⚠️ **Warning**: custom changes will be lost.
jessebot commented 2026-05-14 21:44:27 +00:00 (Migrated from git.smallhack.org)

lets try again

lets try again

Pull request closed

Sign in to join this conversation.
No description provided.