Input validation error in pjsip - #VU150690

 

Input validation error in pjsip - #VU150690

Published: September 17, 2026 / Updated: September 17, 2026


Vulnerability identifier: #VU150690
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the UPnP IGD client's action_get_external_ip() function when parsing a nonnumeric NewExternalIPAddress value from a SOAP response. A remote attacker can provide an attacker-chosen hostname as the address value to stall a libupnp worker thread during name resolution and cause a denial of service.

UPnP support must be built in and explicitly enabled for the vulnerable code path to be reachable.


Affected software

pjsip

Remediation

Install security update from vendor's website.

pjsip - update to 2.18

External References

Related Security Bulletins