PT-2026-38557 · Pjsip · Pjsip

·

CVE-2026-42225

·

Published

2026-05-07

·

Updated

2026-05-07

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.17
Description In GnuTLS builds, the SIP TLS transport (sip transport tls) may accept connections with invalid or untrusted certificates. This occurs even when the application explicitly enables certificate verification through the verify server or verify client variables set to PJ TRUE.
Recommendations Update to version 2.17.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42225
GHSA-X2FV-6J6C-PXMX

Affected Products

Pjsip