Buffer over-read in Asterisk Open Source and Certified Asterisk - CVE-2026-57185

 

Buffer over-read in Asterisk Open Source and Certified Asterisk - CVE-2026-57185

Published: June 26, 2026


Vulnerability identifier: #VU135548
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57185
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the PJSIP MWI body parser when handling a crafted SIP NOTIFY request. A remote user can send a specially crafted SIP NOTIFY request to cause a denial of service.

The attacker must be able to pass SIP authentication either by username and password or by source IP address matching.


Affected software

Asterisk Open Source
Certified Asterisk

How to mitigate CVE-2026-57185

Install security update from vendor's website.

Asterisk Open Source - addressed in versions 20.20.1, 21.12.3, 22.10.1, 23.4.1
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3

External References

Related Security Bulletins