Improper validation of certificate with host mismatch in pjsip - CVE-2026-84975

 

Improper validation of certificate with host mismatch in pjsip - CVE-2026-84975

Published: August 3, 2026 / Updated: September 22, 2026


Vulnerability identifier: #VU140816
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84975
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to impersonate the target server and disclose sensitive information.

The vulnerability exists due to improper validation of certificate with host mismatch in the TLS server identity verification logic in the OpenSSL and GnuTLS backends when processing certificates with a DNS SubjectAltName containing an embedded NUL byte. A remote attacker can present a trusted certificate with a crafted embedded-NUL DNS SubjectAltName to impersonate the target server and disclose sensitive information.

Only applications using the PJSIP TLS or SIPS transport with server verification enabled are vulnerable, and mbedTLS-based deployments are not affected.


Affected software

pjsip
Fedora
asterisk

How to mitigate CVE-2026-84975

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

asterisk - update to 23.5.0-5.fc45

External References

Related Security Bulletins