PT-2026-95553 · Pjsip · Pjsip

CVE-2026-84975

·

Published

2026-09-18

·

Updated

2026-09-20

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.18
Description The OpenSSL and GnuTLS backends in pjlib/src/pj/ssl sock ossl.c and pjlib/src/pj/ssl sock gtls.c use string functions that recalculate length and truncate embedded NUL bytes when copying DNS SubjectAltName values. When server verification is enabled via --tls-verify-server for the PJSIP TLS/SIPS transport, a certificate containing a DNS SubjectAltName consisting of the target hostname prefix, an embedded NUL, and an attacker-controlled suffix may be accepted for the prefix hostname. An attacker with a certificate from a trusted issuer who can intercept the connection can impersonate the target server, complete the SIP session, and obtain REGISTER credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict the use of TLS/SIPS transport to minimize the risk of exploitation.

Exploit

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84975
GHSA-382P-87MH-R3Q8

Affected Products

Pjsip