Vulnerability Description
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pjsip | Pjsip | <= 2.16 |
Related Weaknesses (CWE)
References
- https://github.com/pjsip/pjproject/commit/063b3a155f163cc5a9a1df2c56b6720fd3a0dbPatch
- https://github.com/pjsip/pjproject/security/advisories/GHSA-j29p-pvh2-pvqpPatchVendor Advisory
FAQ
What is CVE-2026-25994?
CVE-2026-25994 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excess...
How severe is CVE-2026-25994?
CVE-2026-25994 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-25994?
Check the references section above for vendor advisories and patch information. Affected products include: Pjsip Pjsip.