Out-of-bounds read in pjsip - CVE-2026-33069
Published: April 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose adjacent heap memory.
The vulnerability exists due to an out-of-bounds read in pjsip_multipart_parse() when parsing SIP multipart bodies. A remote attacker can send a specially crafted SIP message to disclose adjacent heap memory.
Applications that process incoming SIP messages with multipart bodies or SDP content are potentially affected.
Affected software
Asterisk Open Source
Certified Asterisk
How to mitigate CVE-2026-33069
Asterisk Open Source - addressed in versions 20.19.0, 21.12.2, 22.9.0, 23.3.0
Certified Asterisk - addressed in versions 20.7-cert10, 22.8-cert2