#VU125906 Heap-based buffer overflow in pjsip - CVE-2026-26967
Published: April 14, 2026
pjsip
pjsip
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in the H.264 unpacketizer when processing malformed SRTP packets. A remote attacker can send a specially crafted SRTP packet to cause a denial of service.
This issue affects applications that receive video using H.264.