Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pjsip — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting pjsip. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PJSIP is an open-source multimedia communication library primarily utilized for developing Voice over IP (VoIP) applications, including softphones and SIP servers. Its widespread adoption in embedded systems and enterprise telephony solutions has resulted in a significant attack surface, evidenced by thirty-seven recorded Common Vulnerabilities and Exposures. Historically, the codebase has been susceptible to critical flaws such as remote code execution, buffer overflows, and denial-of-service conditions, often stemming from inadequate input validation and memory management errors. While not inherently insecure, its complexity and frequent updates have led to periodic security incidents where attackers exploited parsing vulnerabilities to gain unauthorized access or disrupt services. Developers are advised to prioritize regular patching and rigorous code auditing to mitigate these risks, ensuring the integrity of communication infrastructure that relies on this foundational library for real-time audio and video transmission.

Top products by pjsip: pjproject pjmedia-video
CVE ID Title CVSS Severity Published
CVE-2026-84975 PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends) — pjproject CWE-295 7.4 High 2026-09-18
CVE-2026-77396 PJSIP: Heap buffer overflow in the AVI parser — pjproject CWE-122 6.9 Medium 2026-09-18
CVE-2026-57166 PJSIP: Pre-authentication overflow in the telnet CLI error — pjproject CWE-121 6.3 Medium 2026-09-04
CVE-2026-57165 PJSIP: Pre-authentication overflow in the telnet CLI history — pjproject CWE-121 6.3 Medium 2026-09-04
CVE-2026-57164 PJSIP: Heap overflow in the HTTP client — pjproject CWE-122 8.3 High 2026-09-04
CVE-2026-57163 PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend — pjproject CWE-121 8.8 High 2026-09-04
CVE-2026-57162 PJSIP: Stack overflow parsing SDP a=crypto attributes — pjproject CWE-121 8.8 High 2026-09-04
CVE-2026-57161 PJSIP: Stack overflow handling Service-Route headers in a registration response — pjproject CWE-121 8.8 High 2026-09-04
CVE-2026-57160 PJSIP: SIP message header buffer overflow — pjproject CWE-193 6.9 Medium 2026-09-04
CVE-2026-57159 PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance — pjproject CWE-129 8.4 High 2026-09-04
CVE-2026-42225 GnuTLS backend silently skips certificate chain verification when verify_peer is false — pjproject CWE-295 7.5AI High AI 2026-05-07
CVE-2026-41416 PJSIP: Asymmetric ptime integer overflow in Media Stream — pjproject CWE-190 7.5AI High AI 2026-04-24
CVE-2026-41415 PJSIP: SIP Multipart CID URI Length Underflow — pjproject CWE-125 9.1AI Critical AI 2026-04-24
CVE-2026-40892 PJSIP: Stack buffer overflow in pjsip_auth_create_digest2() — pjproject CWE-121 9.8AI Critical AI 2026-04-21
CVE-2026-40614 PJSIP: Heap buffer overflow in Opus codec decoding — pjproject CWE-122 7.5AI High AI 2026-04-21
CVE-2026-34235 PJSIP: Heap OOB read in VPX unpacketizer — pjproject CWE-125 9.1AI Critical AI 2026-03-31
CVE-2026-33069 PJSIP has an Out-of-bounds Read in SIP multipart parsing — pjproject CWE-125 9.1 - 2026-03-20
CVE-2026-32945 PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser — pjproject CWE-122 9.1 - 2026-03-20
CVE-2026-32942 PJSIP has ICE session use-after-free race conditions — pjproject CWE-416 8.1 - 2026-03-20
CVE-2026-28799 PJSIP: Heap use-after-free in PJSIP presence subscription termination handler — pjproject CWE-416 9.8 - 2026-03-06
CVE-2026-29068 PJSIP: Stack buffer overflow in Opus codec parser — pjproject CWE-121 7.5 - 2026-03-06
CVE-2026-26967 PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer — pjproject CWE-122 9.8 - 2026-02-20
CVE-2026-26203 PJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented NAL — pjmedia-video CWE-416 9.1 - 2026-02-19
CVE-2026-25994 PJSIP has a heap buffer overflow in ICE with long username — pjproject CWE-120 9.8AI Critical AI 2026-02-11
CVE-2025-65102 PJSIP is vulnerable to buffer overflow in Opus PLC — pjproject CWE-120 6.5 - 2025-11-21
CVE-2023-38703 PJSIP has use-after-free vulnerability in SRTP media transport — pjproject CWE-416 9.8 Critical 2023-10-06
CVE-2023-27585 PJSIP 安全漏洞 — pjproject CWE-122 7.5 High 2023-03-14
CVE-2022-23547 Heap buffer overflow in pjproject when decoding STUN message — pjproject CWE-122 6.5 Medium 2022-12-23
CVE-2022-23537 PJSIP vulnerable to heap buffer overflow when decoding STUN message — pjproject CWE-122 6.5 Medium 2022-12-20
CVE-2022-39269 Media transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsip — pjproject CWE-319 9.1 Critical 2022-10-06

This page lists every published CVE security advisory associated with pjsip. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.