Buffer Overflow in PJNATH ICE Session of PJSIP Communication Library
CVE-2026-25994

8.1HIGH

Key Information:

Vendor

Pjsip

Status
Vendor
CVE Published:
11 February 2026

What is CVE-2026-25994?

A buffer overflow vulnerability exists in the PJNATH ICE Session component of the PJSIP multimedia communication library, specifically in versions 2.16 and earlier. This flaw occurs when the system processes excessively long usernames during credential authentication, potentially leading to unauthorized access or denial of service. Developers and users of PJSIP should take immediate action to update their installations to mitigate this vulnerability.

Affected Version(s)

pjproject <= 2.16

References

CVSS V4

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.