Use-after-free in Asterisk Open Source and Certified Asterisk - CVE-2026-57187
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in PJSIP TCP/SDP handling when processing a SIP INVITE over a connection-oriented transport and the TCP connection closes during SDP processing. A remote user can send a specially crafted SIP INVITE and disconnect before Asterisk responds with the 200 OK to cause a denial of service.
The issue has only been reproduced when Address Sanitizer is enabled.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57187
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3