Heap Use-After-Free Vulnerability in PJSIP Communication Library
CVE-2026-28799

8.7HIGH

Key Information:

Vendor

Pjsip

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-28799?

A heap use-after-free vulnerability exists in the PJSIP multimedia communication library's event subscription framework, specifically within the unsubscription process triggered by a SUBSCRIBE message with Expires set to 0. This flaw allows for potential exploitation, primarily affecting versions prior to 2.17. Users are advised to upgrade to the patched version to ensure security and integrity.

Affected Version(s)

pjproject < 2.17

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.