Heap Out-of-Bounds Read Vulnerability in PJSIP Multimedia Communication Library
CVE-2026-34235

6.9MEDIUM

Key Information:

Vendor

Pjsip

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34235?

PJSIP, an open-source multimedia communication library, has a vulnerability in its VP9 RTP unpacketizer that can be exploited due to improper bounds checking when handling crafted VP9 Scalability Structure (SS) data. This flaw allows attackers to read beyond the allocated buffer in the RTP payload, potentially leading to data leakage or application crashes. Users are advised to upgrade to version 2.17 or disable the VP9 codec if it is not required.

Affected Version(s)

pjproject < 2.17

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.