Home

Description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerability is fixed in 2.17.

PUBLISHED Reserved 2026-04-20 | Published 2026-04-24 | Updated 2026-04-24 | Assigner GitHub_M




MEDIUM: 6.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U

Problem types

CWE-125: Out-of-bounds Read

Product status

< 2.17
affected

References

github.com/...roject/security/advisories/GHSA-935m-fmf5-j4pm

github.com/...ommit/4225a93c16661538005017883fbc8f1ea1d5f4b0

cve.org (CVE-2026-41415)

nvd.nist.gov (CVE-2026-41415)

Download JSON