PT-2026-23652 · Pjsip · Pjsip

·

CVE-2026-28799

·

Published

2026-03-06

·

Updated

2026-03-11

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.17
Description PJSIP, a multimedia communication library written in C, contains a heap use-after-free issue within its event subscription framework, specifically in the evsub.c file. This issue is triggered by a presence unsubscription request—a SUBSCRIBE request with an Expires value of 0. Successful exploitation could lead to a crash or potentially code execution.
Recommendations Update to version 2.17 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28799
GHSA-8FJ4-FV9F-HJPC

Affected Products

Pjsip