NULL pointer dereference in Janus WebRTC Server - #VU151860

 

NULL pointer dereference in Janus WebRTC Server - #VU151860

Published: September 23, 2026


Vulnerability identifier: #VU151860
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the TextRoom message handler when processing a datachannel message containing a non-string element in the tos array. A remote user can send a crafted datachannel message containing a non-string tos array element to cause a denial of service.

The crash terminates the Janus process and drops all TextRoom rooms and users on the instance.


Affected software

Janus WebRTC Server

Remediation

Install security update from vendor's website.

Janus WebRTC Server - addressed in versions 0.16.2, 1.4.2

External References

Related Security Bulletins