Buffer over-read in Asterisk Open Source and Certified Asterisk - CVE-2026-57185
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the PJSIP MWI body parser when handling a crafted SIP NOTIFY request. A remote user can send a specially crafted SIP NOTIFY request to cause a denial of service.
The attacker must be able to pass SIP authentication either by username and password or by source IP address matching.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57185
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3