Stack-based buffer overflow in pjsip - CVE-2026-57161
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in update_service_route() in pjsua_acc.c when processing Service-Route headers in a registration response. A remote attacker can send a specially crafted registration response with an excessive number of Service-Route headers to cause a denial of service.
The issue affects applications that use the PJSUA/PJSUA2 account API for registration, and the malicious response may originate from a compromised or malicious registrar or from a spoofed response over unprotected transports.