Use-after-free in pjsip - #VU150689
Published: September 17, 2026 / Updated: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the application to adopt a hostile IGD as its primary gateway.
The vulnerability exists due to a use-after-free in the UPnP IGD client's action_get_external_ip() function when processing a SOAP response containing an invalid NewExternalIPAddress value. A remote attacker can provide a crafted SOAP response to cause the application to adopt a hostile IGD as its primary gateway.
UPnP support must be built in and explicitly enabled for the vulnerable code path to be reachable.