PT-2026-86166 · Pjsip · Pjsip

CVE-2026-57160

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to commit d6a0e7f
Description A buffer overflow exists in the pjsip generic array hdr print() function within pjsip/src/pjsip/sip msg.c, which is responsible for serializing generic array headers such as Allow, Require, Supported, and Unsupported. Under specific output-buffer boundary conditions, the function may write a single fixed byte beyond the end of the buffer. This issue primarily affects applications that parse and re-serialize incoming SIP requests, such as proxies, Session Border Controllers (SBC), or Back-to-Back User Agents (B2BUA), allowing a remote peer to influence the serialized message.
Recommendations Update to the version containing commit d6a0e7f.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57160
GHSA-277R-3Q2J-MXCW

Affected Products

Pjsip