PT-2026-7717 · Pjsip+1 · Pjsip+1

Gherasimgeorgemarian82

·

Published

2026-02-11

·

Updated

2026-03-24

·

CVE-2026-25994

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.17
Description PJSIP is a multimedia communication library implemented in C. A buffer overflow condition exists in the PJNATH ICE Session component when handling credentials containing overly long usernames. This can potentially lead to remote code execution without authentication.
Recommendations Upgrade to version 2.17 or later.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-25994
GHSA-J29P-PVH2-PVQP
USN-8122-1

Affected Products

Pjsip
Ubuntu