Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pjproject — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in pjproject, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for the product pjproject. It collects security advisories associated with this software package, covering the time range of available public records. Here you can track the vendor's disclosure history, understand the specific weakness classes affecting this library, and review the vulnerability history for pjproject to identify recurring patterns or critical gaps. The data is presented in a structured format to facilitate analysis of the product's security posture over time.

Vendor: pjsip

CVE ID Title CVSS Severity Published
CVE-2026-84975 PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends) CWE-295 7.4 High 2026-09-18
CVE-2026-77396 PJSIP: Heap buffer overflow in the AVI parser CWE-122 6.9 Medium 2026-09-18
CVE-2026-57166 PJSIP: Pre-authentication overflow in the telnet CLI error CWE-121 6.3 Medium 2026-09-04
CVE-2026-57165 PJSIP: Pre-authentication overflow in the telnet CLI history CWE-121 6.3 Medium 2026-09-04
CVE-2026-57164 PJSIP: Heap overflow in the HTTP client CWE-122 8.3 High 2026-09-04
CVE-2026-57163 PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend CWE-121 8.8 High 2026-09-04
CVE-2026-57162 PJSIP: Stack overflow parsing SDP a=crypto attributes CWE-121 8.8 High 2026-09-04
CVE-2026-57161 PJSIP: Stack overflow handling Service-Route headers in a registration response CWE-121 8.8 High 2026-09-04
CVE-2026-57160 PJSIP: SIP message header buffer overflow CWE-193 6.9 Medium 2026-09-04
CVE-2026-57159 PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance CWE-129 8.4 High 2026-09-04
CVE-2026-42225 GnuTLS backend silently skips certificate chain verification when verify_peer is false CWE-295 7.5AI High AI 2026-05-07
CVE-2026-41416 PJSIP: Asymmetric ptime integer overflow in Media Stream CWE-190 7.5AI High AI 2026-04-24
CVE-2026-41415 PJSIP: SIP Multipart CID URI Length Underflow CWE-125 9.1AI Critical AI 2026-04-24
CVE-2026-40892 PJSIP: Stack buffer overflow in pjsip_auth_create_digest2() CWE-121 9.8AI Critical AI 2026-04-21
CVE-2026-40614 PJSIP: Heap buffer overflow in Opus codec decoding CWE-122 7.5AI High AI 2026-04-21
CVE-2026-34235 PJSIP: Heap OOB read in VPX unpacketizer CWE-125 9.1AI Critical AI 2026-03-31
CVE-2026-33069 PJSIP has an Out-of-bounds Read in SIP multipart parsing CWE-125 9.1 - 2026-03-20
CVE-2026-32945 PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser CWE-122 9.1 - 2026-03-20
CVE-2026-32942 PJSIP has ICE session use-after-free race conditions CWE-416 8.1 - 2026-03-20
CVE-2026-28799 PJSIP: Heap use-after-free in PJSIP presence subscription termination handler CWE-416 9.8 - 2026-03-06
CVE-2026-29068 PJSIP: Stack buffer overflow in Opus codec parser CWE-121 7.5 - 2026-03-06
CVE-2026-26967 PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer CWE-122 9.8 - 2026-02-20
CVE-2026-25994 PJSIP has a heap buffer overflow in ICE with long username CWE-120 9.8AI Critical AI 2026-02-11
CVE-2025-65102 PJSIP is vulnerable to buffer overflow in Opus PLC CWE-120 6.5 - 2025-11-21
CVE-2023-38703 PJSIP has use-after-free vulnerability in SRTP media transport CWE-416 9.8 Critical 2023-10-06
CVE-2023-27585 PJSIP 安全漏洞 CWE-122 7.5 High 2023-03-14
CVE-2022-23547 Heap buffer overflow in pjproject when decoding STUN message CWE-122 6.5 Medium 2022-12-23
CVE-2022-23537 PJSIP vulnerable to heap buffer overflow when decoding STUN message CWE-122 6.5 Medium 2022-12-20
CVE-2022-39269 Media transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsip CWE-319 9.1 Critical 2022-10-06
CVE-2022-39244 Buffer overflow in pjlib scanner and pjmedia CWE-120 7.5 High 2022-10-06

All 47 known CVE vulnerabilities affecting pjproject with full Chinese analysis, references, and POCs where available.