Out-of-bounds read in pjsip - CVE-2026-33069

 

Out-of-bounds read in pjsip - CVE-2026-33069

Published: April 14, 2026


Vulnerability identifier: #VU125901
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33069
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose adjacent heap memory.

The vulnerability exists due to an out-of-bounds read in pjsip_multipart_parse() when parsing SIP multipart bodies. A remote attacker can send a specially crafted SIP message to disclose adjacent heap memory.

Applications that process incoming SIP messages with multipart bodies or SDP content are potentially affected.


Affected software

pjsip
Asterisk Open Source
Certified Asterisk

How to mitigate CVE-2026-33069

Install security update from vendor's website.

pjsip - update to 2.17
Asterisk Open Source - addressed in versions 20.19.0, 21.12.2, 22.9.0, 23.3.0
Certified Asterisk - addressed in versions 20.7-cert10, 22.8-cert2

External References

Related Security Bulletins