pjproject
pjsip- Software type
- —
- Catalog vulnerabilities
- 45
Severity across 45 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 45 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 45 vulnerability records affecting pjproject.
Among the 45 records analyzed by CyStack, 33 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-57166PJSIP: Pre-authentication overflow in the telnet CLI error | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
CVE-2026-57165PJSIP: Pre-authentication overflow in the telnet CLI history | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
CVE-2026-57164PJSIP: Heap overflow in the HTTP client | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57163PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57162PJSIP: Stack overflow parsing SDP a=crypto attributes | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57161PJSIP: Stack overflow handling Service-Route headers in a registration response | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-57160PJSIP: SIP message header buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityMedium |
CVE-2026-57159PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance | Exploitation statusNot known exploited | FixNot confirmed | Published09/04/2026 | SeverityHigh |
CVE-2026-42225GnuTLS backend silently skips certificate chain verification when verify_peer is false | Exploitation statusNot known exploited | FixYes | Published05/07/2026 | SeverityHigh |
CVE-2026-41416PJSIP: Asymmetric ptime integer overflow in Media Stream | Exploitation statusNot known exploited | FixYes | Published04/24/2026 | SeverityHigh |
CVE-2026-41415PJSIP: SIP Multipart CID URI Length Underflow | Exploitation statusNot known exploited | FixYes | Published04/24/2026 | SeverityMedium |
CVE-2026-40892PJSIP: Stack buffer overflow in pjsip_auth_create_digest2() | Exploitation statusNot known exploited | FixNot confirmed | Published04/21/2026 | SeverityHigh |
CVE-2026-40614PJSIP: Heap buffer overflow in Opus codec decoding | Exploitation statusNot known exploited | FixNot confirmed | Published04/21/2026 | SeverityHigh |
CVE-2026-34235PJSIP: Heap OOB read in VPX unpacketizer | Exploitation statusNot known exploited | FixYes | Published03/31/2026 | SeverityMedium |
CVE-2026-33069PJSIP has an Out-of-bounds Read in SIP multipart parsing | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityMedium |
CVE-2026-32945PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityHigh |
CVE-2026-32942PJSIP has ICE session use-after-free race conditions | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityHigh |
CVE-2026-28799PJSIP: Heap use-after-free in PJSIP presence subscription termination handler | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityHigh |
CVE-2026-29068PJSIP: Stack buffer overflow in Opus codec parser | Exploitation statusNot known exploited | FixYes | Published03/06/2026 | SeverityHigh |
CVE-2026-26967PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityHigh |
CVE-2026-25994PJSIP has a heap buffer overflow in ICE with long username | Exploitation statusNot known exploited | FixNot confirmed | Published02/11/2026 | SeverityHigh |
CVE-2025-65102PJSIP is vulnerable to buffer overflow in Opus PLC | Exploitation statusNot known exploited | FixYes | Published11/21/2025 | SeverityHigh |
CVE-2023-38703PJSIP has use-after-free vulnerability in SRTP media transport | Exploitation statusNot known exploited | FixYes | Published10/06/2023 | SeverityCritical |
CVE-2023-27585CVE-2023-27585 | Exploitation statusNot known exploited | FixYes | Published03/14/2023 | SeverityHigh |
CVE-2022-23547Heap buffer overflow in pjproject when decoding STUN message | Exploitation statusNot known exploited | FixYes | Published12/23/2022 | SeverityMedium |
CVE-2022-23537PJSIP vulnerable to heap buffer overflow when decoding STUN message | Exploitation statusNot known exploited | FixYes | Published12/20/2022 | SeverityMedium |
CVE-2022-39269Media transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsip | Exploitation statusNot known exploited | FixYes | Published10/06/2022 | SeverityCritical |
CVE-2022-39244Buffer overflow in pjlib scanner and pjmedia | Exploitation statusNot known exploited | FixNot confirmed | Published10/06/2022 | SeverityHigh |
CVE-2022-31031Potential stack buffer overflow when parsing message as a STUN client | Exploitation statusNot known exploited | FixYes | Published06/07/2022 | SeverityCritical |
CVE-2022-24792Potential infinite loop when parsing WAV format file in PJSIP | Exploitation statusNot known exploited | FixYes | Published04/25/2022 | SeverityHigh |
CVE-2022-24786Potential out-of-bound read/write in PJSIP | Exploitation statusNot known exploited | FixYes | Published04/06/2022 | SeverityCritical |
CVE-2022-24793Potential heap buffer overflow when parsing DNS packets in PJSIP | Exploitation statusNot known exploited | FixYes | Published04/06/2022 | SeverityHigh |
CVE-2022-24763Infinite Loop in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published03/30/2022 | SeverityHigh |
CVE-2022-24764Stack buffer overflow in pjproject | Exploitation statusNot known exploited | FixYes | Published03/22/2022 | SeverityHigh |
CVE-2022-24754Buffer overflow in pjsip | Exploitation statusNot known exploited | FixYes | Published03/11/2022 | SeverityHigh |
CVE-2022-23608Use after free in PJSIP | Exploitation statusNot known exploited | FixYes | Published02/22/2022 | SeverityHigh |
CVE-2022-21723Out-of-bounds read in multipart parsing in PJSIP | Exploitation statusNot known exploited | FixYes | Published01/27/2022 | SeverityCritical |
CVE-2022-21722Potential out-of-bound read during RTP/RTCP parsing in PJSIP | Exploitation statusNot known exploited | FixYes | Published01/27/2022 | SeverityCritical |
CVE-2021-41141Missing release of locks in PJSIP | Exploitation statusNot known exploited | FixNot confirmed | Published01/04/2022 | SeverityMedium |
CVE-2021-43845Prevent out-of-bounds read in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published12/27/2021 | SeverityHigh |
CVE-2021-37706Potential integer underflow upon receiving STUN message in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published12/22/2021 | SeverityHigh |
CVE-2021-43804Out-of-bounds read when parsing RTCP BYE message in PJSIP | Exploitation statusNot confirmed | FixNot confirmed | Published12/22/2021 | SeverityHigh |
CVE-2021-32686Denial of Service in PJSIP | Exploitation statusNot confirmed | FixYes | Published07/23/2021 | SeverityMedium |
CVE-2021-21375Crash in receiving updated SDP answer after initial SDP negotiation failed | Exploitation statusNot confirmed | FixNot confirmed | Published03/10/2021 | SeverityMedium |
CVE-2020-15260Existing TLS connections can be reused without checking remote hostname | Exploitation statusNot confirmed | FixNot confirmed | Published03/10/2021 | SeverityMedium |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan