PT-2026-86166 · Pjsip · Pjsip
CVE-2026-57160
·
Published
2026-09-04
·
Updated
2026-09-04
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PJSIP versions prior to commit d6a0e7f
Description
A buffer overflow exists in the
pjsip generic array hdr print() function within pjsip/src/pjsip/sip msg.c, which is responsible for serializing generic array headers such as Allow, Require, Supported, and Unsupported. Under specific output-buffer boundary conditions, the function may write a single fixed byte beyond the end of the buffer. This issue primarily affects applications that parse and re-serialize incoming SIP requests, such as proxies, Session Border Controllers (SBC), or Back-to-Back User Agents (B2BUA), allowing a remote peer to influence the serialized message.Recommendations
Update to the version containing commit d6a0e7f.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pjsip