Improper Certificate Validation in pjsip - #VU127458
Published: April 24, 2026
pjsip
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass mutual-tls authentication.
The vulnerability exists due to improper certificate validation in sip_transport_tls when handling tls handshakes on GnuTLS builds with verify_client enabled. A remote attacker can present an invalid or untrusted client certificate to bypass mutual-tls authentication.
Only GnuTLS builds configured with --with-gnutls are vulnerable.