Out-of-bounds read in pjsip - #VU126320
Published: April 16, 2026
pjsip
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in Content-ID URI parser when parsing a malformed Content-ID URI in a SIP multipart message body. A remote attacker can send a specially crafted SIP message with a multipart body to disclose sensitive information.