CVE 8.1 HIGH

PJSIP has a heap buffer overflow in ICE with long username_CVE-2026-25994

8.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U

Description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

Basic Information

ID CVE-2026-25994
Source GitHub_M
Published Feb 11, 2026 at 20:56

Affected Product

Vendor pjsip
Product pjproject
Version <= 2.16
Affected Versions pjsip pjproject <= 2.16

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.