Buffer over-read in Asterisk Open Source and Certified Asterisk - CVE-2026-57185
Published: June 26, 2026
Asterisk Open Source
Certified Asterisk
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the PJSIP MWI body parser when handling a crafted SIP NOTIFY request. A remote user can send a specially crafted SIP NOTIFY request to cause a denial of service.
The attacker must be able to pass SIP authentication either by username and password or by source IP address matching.