Insufficient verification of data authenticity in pjsip - #VU140817
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect media or signaling traffic and cause a denial of service.
The vulnerability exists due to improper authentication in the legacy simple STUN client when processing STUN Binding Responses for public-address discovery. A remote attacker can send a forged Binding Response to redirect media or signaling traffic and cause a denial of service.
Only applications that use a STUN server without ICE for public-address discovery are affected. Applications that use ICE for STUN, or that do not configure a STUN server, are not affected.