Heap-based buffer overflow in pjsip - #VU125903
Published: April 14, 2026
pjsip
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service or corrupt memory.
The vulnerability exists due to heap-based buffer overflow in the Opus codec decode path when decoding specially crafted incoming Opus audio frames. A remote attacker can send a specially crafted incoming audio packet to cause a denial of service or corrupt memory.
This affects applications that use the Opus audio codec in the receiving direction.