Out-of-bounds read in pjsip - #VU140818

 

Out-of-bounds read in pjsip - #VU140818

Published: August 3, 2026


Vulnerability identifier: #VU140818
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.

The vulnerability exists due to out-of-bounds read in the SIP message serializer when re-serializing received SIP messages containing a specially crafted multipart body. A remote attacker can send a specially crafted SIP message with an empty multipart body to disclose sensitive information or cause a denial of service.

Only applications that re-encode incoming multipart bodies, such as SIP proxies that forward requests, are affected.


Affected software

pjsip

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins