pjproject
pjsip- Product type
- Other
- Catalog vulnerabilities
- 47
Severity across 47 analyzed records
en
Verify to analyze this security profile
As of 10/02/2026, within CyStack's analyzed data, pjproject has 10 security vulnerabilities published in the last 90 days. Of these, 6 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of pjproject and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-84975PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends) | Exploitation statusNot known exploited | FixNot confirmed | Published09/18/2026 | SeverityHigh |
CVE-2026-77396PJSIP: Heap buffer overflow in the AVI parser | Exploitation statusNot known exploited | FixNot confirmed | Published09/18/2026 | SeverityMedium |
CVE-2026-57166PJSIP: Pre-authentication overflow in the telnet CLI error | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
CVE-2026-57165PJSIP: Pre-authentication overflow in the telnet CLI history | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
CVE-2026-57164PJSIP: Heap overflow in the HTTP client | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57163PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57162PJSIP: Stack overflow parsing SDP a=crypto attributes | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57161PJSIP: Stack overflow handling Service-Route headers in a registration response | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57160PJSIP: SIP message header buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
CVE-2026-57159PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-42225GnuTLS backend silently skips certificate chain verification when verify_peer is false | Exploitation statusNot known exploited | FixYes | Published05/07/2026 | SeverityHigh |
CVE-2026-41416PJSIP: Asymmetric ptime integer overflow in Media Stream | Exploitation statusNot known exploited | FixYes | Published04/24/2026 | SeverityHigh |
CVE-2026-41415PJSIP: SIP Multipart CID URI Length Underflow | Exploitation statusNot known exploited | FixYes | Published04/24/2026 | SeverityMedium |
CVE-2026-40892PJSIP: Stack buffer overflow in pjsip_auth_create_digest2() | Exploitation statusNot known exploited | FixNot confirmed | Published04/21/2026 | SeverityHigh |
CVE-2026-40614PJSIP: Heap buffer overflow in Opus codec decoding | Exploitation statusNot known exploited | FixNot confirmed | Published04/21/2026 | SeverityHigh |
CVE-2026-34235PJSIP: Heap OOB read in VPX unpacketizer | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityMedium |
CVE-2026-33069PJSIP has an Out-of-bounds Read in SIP multipart parsing | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityMedium |
CVE-2026-32945PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityHigh |
CVE-2026-32942PJSIP has ICE session use-after-free race conditions | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityHigh |
CVE-2026-28799PJSIP: Heap use-after-free in PJSIP presence subscription termination handler | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityHigh |
CVE-2026-29068PJSIP: Stack buffer overflow in Opus codec parser | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityHigh |
CVE-2026-26967PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityHigh |
CVE-2026-25994PJSIP has a heap buffer overflow in ICE with long username | Exploitation statusNot known exploited | FixNot confirmed | Published02/11/2026 | SeverityHigh |
CVE-2025-65102PJSIP is vulnerable to buffer overflow in Opus PLC | Exploitation statusNot known exploited | FixYes | Published11/21/2025 | SeverityHigh |
CVE-2023-38703PJSIP has use-after-free vulnerability in SRTP media transport | Exploitation statusNot known exploited | FixYes | Published10/06/2023 | SeverityCritical |
CVE-2023-27585 | Exploitation statusNot known exploited | FixYes | Published03/14/2023 | SeverityHigh |
CVE-2022-23547Heap buffer overflow in pjproject when decoding STUN message | Exploitation statusNot known exploited | FixYes | Published12/23/2022 | SeverityMedium |
CVE-2022-23537PJSIP vulnerable to heap buffer overflow when decoding STUN message | Exploitation statusNot known exploited | FixYes | Published12/20/2022 | SeverityMedium |
CVE-2022-39269Media transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsip | Exploitation statusNot known exploited | FixYes | Published10/06/2022 | SeverityCritical |
CVE-2022-39244Buffer overflow in pjlib scanner and pjmedia | Exploitation statusNot known exploited | FixNot confirmed | Published10/06/2022 | SeverityHigh |
CVE-2022-31031Potential stack buffer overflow when parsing message as a STUN client | Exploitation statusNot known exploited | FixYes | Published06/07/2022 | SeverityCritical |
CVE-2022-24792Potential infinite loop when parsing WAV format file in PJSIP | Exploitation statusNot known exploited | FixYes | Published04/25/2022 | SeverityHigh |
CVE-2022-24793Potential heap buffer overflow when parsing DNS packets in PJSIP | Exploitation statusNot known exploited | FixYes | Published04/06/2022 | SeverityHigh |
CVE-2022-24786Potential out-of-bound read/write in PJSIP | Exploitation statusNot known exploited | FixYes | Published04/06/2022 | SeverityCritical |
CVE-2022-24763Infinite Loop in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityHigh |
CVE-2022-24764Stack buffer overflow in pjproject | Exploitation statusNot known exploited | FixYes | Published03/22/2022 | SeverityHigh |
CVE-2022-24754Buffer overflow in pjsip | Exploitation statusNot known exploited | FixYes | Published03/11/2022 | SeverityHigh |
CVE-2022-23608Use after free in PJSIP | Exploitation statusNot known exploited | FixYes | Published02/22/2022 | SeverityHigh |
CVE-2022-21722Potential out-of-bound read during RTP/RTCP parsing in PJSIP | Exploitation statusNot known exploited | FixYes | Published01/27/2022 | SeverityCritical |
CVE-2022-21723Out-of-bounds read in multipart parsing in PJSIP | Exploitation statusNot known exploited | FixYes | Published01/27/2022 | SeverityCritical |
CVE-2021-41141Missing release of locks in PJSIP | Exploitation statusNot known exploited | FixNot confirmed | Published01/04/2022 | SeverityMedium |
CVE-2021-43845Prevent out-of-bounds read in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published12/27/2021 | SeverityHigh |
CVE-2021-37706Potential integer underflow upon receiving STUN message in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published12/22/2021 | SeverityHigh |
CVE-2021-43804Out-of-bounds read when parsing RTCP BYE message in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published12/22/2021 | SeverityHigh |
CVE-2021-32686Denial of Service in PJSIP | Exploitation statusNot confirmed | FixYes | Published07/23/2021 | SeverityMedium |
CVE-2021-21375Crash in receiving updated SDP answer after initial SDP negotiation failed | Exploitation statusNot confirmed | FixNot confirmed | Published03/10/2021 | SeverityMedium |
CVE-2020-15260Existing TLS connections can be reused without checking remote hostname | Exploitation statusNot confirmed | FixNot confirmed | Published03/10/2021 | SeverityMedium |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan