NULL pointer dereference in pjsip - #VU150693
Published: September 17, 2026 / Updated: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in calculate_response_expiration() in the SIP registration client when processing a 2xx response to an outgoing REGISTER containing a wildcard Contact header. A remote attacker can send a crafted 2xx response containing a wildcard Contact header to cause a denial of service.
The affected registration-client path is enabled by default.