#VU125905 Use-after-free in pjsip - CVE-2026-26203
Published: April 14, 2026
pjsip
pjsip
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the H.264 packetizer when processing malformed H.264 bitstreams without NAL unit start codes during packetization of fragmented NAL units. A remote attacker can send a specially crafted H.264 bitstream to cause a denial of service.
The issue affects applications sending video using H.264 with a packetization mode other than single NAL.