Improper validation of certificate with host mismatch in pjsip - #VU140816

 

Improper validation of certificate with host mismatch in pjsip - #VU140816

Published: August 3, 2026


Vulnerability identifier: #VU140816
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to impersonate the target server and disclose sensitive information.

The vulnerability exists due to improper validation of certificate with host mismatch in the TLS server identity verification logic in the OpenSSL and GnuTLS backends when processing certificates with a DNS SubjectAltName containing an embedded NUL byte. A remote attacker can present a trusted certificate with a crafted embedded-NUL DNS SubjectAltName to impersonate the target server and disclose sensitive information.

Only applications using the PJSIP TLS or SIPS transport with server verification enabled are vulnerable, and mbedTLS-based deployments are not affected.


Affected software

pjsip

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins