Use-after-free in Janus WebRTC Server - #VU151862

 

Use-after-free in Janus WebRTC Server - #VU151862

Published: September 23, 2026


Vulnerability identifier: #VU151862
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise confidentiality, integrity, and availability.

The vulnerability exists due to use-after-free in the Janus SIP and NoSIP plugins when handling peer messages that look up a destroyed session by its unique ID. A remote user can send ordinary peer messages referencing a stale unique ID to compromise confidentiality, integrity, and availability.

No race condition or admin API access is required.


Affected software

Janus WebRTC Server

Remediation

Install security update from vendor's website.

Janus WebRTC Server - addressed in versions 0.16.2, 1.4.2

External References

Related Security Bulletins