CVE-2026-26203

medium

Description

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.

References

https://github.com/pjsip/pjproject/security/advisories/GHSA-p965-mf7j-gwv8

https://github.com/pjsip/pjproject/commit/5aee54f09d4f91538d55279d7316591b28fded6c

Details

Source: Mitre, NVD

Published: 2026-02-19

Updated: 2026-02-20

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Severity: Medium

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L

Severity: Medium

EPSS

EPSS: 0.00014