Use-after-free in pjsip - #VU150689

 

Use-after-free in pjsip - #VU150689

Published: September 17, 2026 / Updated: September 17, 2026


Vulnerability identifier: #VU150689
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause the application to adopt a hostile IGD as its primary gateway.

The vulnerability exists due to a use-after-free in the UPnP IGD client's action_get_external_ip() function when processing a SOAP response containing an invalid NewExternalIPAddress value. A remote attacker can provide a crafted SOAP response to cause the application to adopt a hostile IGD as its primary gateway.

UPnP support must be built in and explicitly enabled for the vulnerable code path to be reachable.


Affected software

pjsip

Remediation

Install security update from vendor's website.

pjsip - update to 2.18

External References

Related Security Bulletins