NULL pointer dereference in Asterisk Open Source and Certified Asterisk - CVE-2026-57195

 

NULL pointer dereference in Asterisk Open Source and Certified Asterisk - CVE-2026-57195

Published: June 26, 2026


Vulnerability identifier: #VU135542
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57195
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the http ami digest authentication handler when processing crafted HTTP requests for AMI digest authentication. A remote attacker can send a specially crafted HTTP request to cause a denial of service.

The issue is exploitable only when the Asterisk HTTP web server is enabled, the Asterisk Manager Interface is enabled, and access to the AMI via HTTP is enabled.


Affected software

Asterisk Open Source
Certified Asterisk

How to mitigate CVE-2026-57195

Install security update from vendor's website.

Asterisk Open Source - addressed in versions 20.20.1, 21.12.3, 22.10.1, 23.4.1
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3

External References

Related Security Bulletins