PT-2026-38557 · Pjsip · Pjsip

Feynman-Hou

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-42225

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.17
Description In GnuTLS builds, the SIP TLS transport (sip transport tls) may accept connections with invalid or untrusted certificates. This occurs even when the application explicitly enables certificate verification through the verify server or verify client variables set to PJ TRUE.
Recommendations Update to version 2.17.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42225

Affected Products

Pjsip