Improper validation of certificate with host mismatch in pjsip - #VU140816
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate the target server and disclose sensitive information.
The vulnerability exists due to improper validation of certificate with host mismatch in the TLS server identity verification logic in the OpenSSL and GnuTLS backends when processing certificates with a DNS SubjectAltName containing an embedded NUL byte. A remote attacker can present a trusted certificate with a crafted embedded-NUL DNS SubjectAltName to impersonate the target server and disclose sensitive information.
Only applications using the PJSIP TLS or SIPS transport with server verification enabled are vulnerable, and mbedTLS-based deployments are not affected.