Search CVE reports


Toggle filters

1 – 10 of 47 results


CVE-2026-42225

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) can accept connections with invalid or untrusted certificates even...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-41416

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-41415

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-40892

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed digest credentials...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-40614

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames due to insufficient buffer size validation in the Opus codec...

2 affected packages

asterisk, pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-34235

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability...

1 affected package

pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-33069

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past...

1 affected package

pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-32945

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's...

1 affected package

pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-32942

Medium priority
Needs evaluation

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between...

1 affected package

pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2026-29068

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than...

1 affected package

pjproject

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pjproject Not in release Not in release Not in release Vulnerable
Show less packages