Remote Out-of-Bounds Read and Write in PJSIP Multimedia Communication Library
CVE-2026-57159

8.4HIGH

Key Information:

Vendor

Pjsip

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-57159?

The PJSIP multimedia communication library is susceptible to a remote out-of-bounds read and write vulnerability due to inadequate bounds validation in its SDP negotiator. This issue arises when the remote payload-type map maintenance feature is enabled, which allows a crafted remote SDP to access memory outside predefined tables. While the potential impacts include memory corruption and denial of service, the extent of exploitation for code execution has not been demonstrated. This vulnerability has been addressed in commit 673b978, but environments utilizing this feature should ensure they are patched.

Affected Version(s)

pjproject < 673b978aab1fe3ab874247be32c871acc880cbeb

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.