216.73.216.233

CVE-2026-26203

· Published 19/02/2026 20:25 · Modified 20/02/2026 20:12

Labels: CVE-2026-26203 2026-02-19CVE-2026-26203CWE-416[email protected]

Essential information

Published
19/02/2026 20:25
Modified
20/02/2026 20:12
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pjsip / pjsip cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:*

References