#VU125907 Out-of-bounds read in pjsip - CVE-2026-34235
Published: April 14, 2026
pjsip
pjsip
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the VP9 RTP unpacketizer when parsing crafted VP9 scalability structure data. A remote attacker can send crafted VP9 RTP media to disclose sensitive information.
Only applications with video support enabled through PJMEDIA_HAS_VIDEO that receive VP9 RTP media are affected.