{"id":"CVE-2026-57160","title":"PJSIP is a free and open source multimedia communication library written in C","summary":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic arr…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-193"],"vendor":"teluu","product":"pjsip","affected":["pjsip <= 2.17"],"published":"2026-09-04","updated":"2026-09-11","sourceUpdated":"2026-09-11T15:31:44.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57160","references":[{"url":"https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c","label":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57160.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-57160"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-57160"}],"tags":["nvd","cve.org","csaf","vex","red-hat","score-dispute"],"epss":0.00412,"epssPercentile":0.32747,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T16:50:27.194449Z"},"scores":{"nvd":5.3,"cna":6.9,"vendor":7.5},"ingestedAt":"2026-09-08T18:07:34.888Z","slug":"CVE-2026-57160","body":"## Overview\n\nPJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.\n\n## Affected\n\n- `pjsip <= 2.17`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57160.json)","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201809,"id":"CVE-2026-57160","ts":1789399726437,"field":"cvss","old":"6.9","new":"5.3"},{"seq":200539,"id":"CVE-2026-57160","ts":1789397379308,"field":"cvss","old":"5.3","new":"6.9"},{"seq":198456,"id":"CVE-2026-57160","ts":1789391969160,"field":"cvss","old":"6.9","new":"5.3"},{"seq":196249,"id":"CVE-2026-57160","ts":1789383585805,"field":"cvss","old":"5.3","new":"6.9"},{"seq":195178,"id":"CVE-2026-57160","ts":1789380475412,"field":"cvss","old":"6.9","new":"5.3"},{"seq":193965,"id":"CVE-2026-57160","ts":1789378522875,"field":"cvss","old":"5.3","new":"6.9"},{"seq":192752,"id":"CVE-2026-57160","ts":1789376407603,"field":"cvss","old":"6.9","new":"5.3"},{"seq":191539,"id":"CVE-2026-57160","ts":1789373424564,"field":"cvss","old":"5.3","new":"6.9"},{"seq":190324,"id":"CVE-2026-57160","ts":1789369300563,"field":"cvss","old":"6.9","new":"5.3"},{"seq":189111,"id":"CVE-2026-57160","ts":1789368267753,"field":"cvss","old":"5.3","new":"6.9"},{"seq":187894,"id":"CVE-2026-57160","ts":1789365143733,"field":"cvss","old":"6.9","new":"5.3"},{"seq":186681,"id":"CVE-2026-57160","ts":1789363276027,"field":"cvss","old":"5.3","new":"6.9"},{"seq":185467,"id":"CVE-2026-57160","ts":1789361101748,"field":"cvss","old":"6.9","new":"5.3"},{"seq":184254,"id":"CVE-2026-57160","ts":1789358156410,"field":"cvss","old":"5.3","new":"6.9"},{"seq":182505,"id":"CVE-2026-57160","ts":1789354222818,"field":"cvss","old":"6.9","new":"5.3"},{"seq":181298,"id":"CVE-2026-57160","ts":1789353123662,"field":"cvss","old":"5.3","new":"6.9"},{"seq":180091,"id":"CVE-2026-57160","ts":1789350169497,"field":"cvss","old":"6.9","new":"5.3"},{"seq":178884,"id":"CVE-2026-57160","ts":1789348102188,"field":"cvss","old":"5.3","new":"6.9"},{"seq":177677,"id":"CVE-2026-57160","ts":1789346277984,"field":"cvss","old":"6.9","new":"5.3"},{"seq":176470,"id":"CVE-2026-57160","ts":1789343019245,"field":"cvss","old":"5.3","new":"6.9"},{"seq":174587,"id":"CVE-2026-57160","ts":1789334771969,"field":"cvss","old":"6.9","new":"5.3"},{"seq":173382,"id":"CVE-2026-57160","ts":1789333515634,"field":"cvss","old":"5.3","new":"6.9"},{"seq":172196,"id":"CVE-2026-57160","ts":1789331018420,"field":"cvss","old":"6.9","new":"5.3"},{"seq":171010,"id":"CVE-2026-57160","ts":1789328617890,"field":"cvss","old":"5.3","new":"6.9"},{"seq":169805,"id":"CVE-2026-57160","ts":1789327051362,"field":"cvss","old":"6.9","new":"5.3"},{"seq":168600,"id":"CVE-2026-57160","ts":1789323660327,"field":"cvss","old":"5.3","new":"6.9"},{"seq":167395,"id":"CVE-2026-57160","ts":1789319579064,"field":"cvss","old":"6.9","new":"5.3"},{"seq":166190,"id":"CVE-2026-57160","ts":1789318562487,"field":"cvss","old":"5.3","new":"6.9"},{"seq":164985,"id":"CVE-2026-57160","ts":1789315704133,"field":"cvss","old":"6.9","new":"5.3"},{"seq":163780,"id":"CVE-2026-57160","ts":1789313454116,"field":"cvss","old":"5.3","new":"6.9"},{"seq":162575,"id":"CVE-2026-57160","ts":1789311820911,"field":"cvss","old":"6.9","new":"5.3"},{"seq":161370,"id":"CVE-2026-57160","ts":1789308525198,"field":"cvss","old":"5.3","new":"6.9"},{"seq":160875,"id":"CVE-2026-57160","ts":1789304486810,"field":"cvss","old":"6.9","new":"5.3"},{"seq":160422,"id":"CVE-2026-57160","ts":1789303992010,"field":"cvss","old":"5.3","new":"6.9"},{"seq":159483,"id":"CVE-2026-57160","ts":1789300402603,"field":"cvss","old":"6.9","new":"5.3"},{"seq":158713,"id":"CVE-2026-57160","ts":1789299495544,"field":"cvss","old":"5.3","new":"6.9"},{"seq":157677,"id":"CVE-2026-57160","ts":1789296582362,"field":"cvss","old":"6.9","new":"5.3"},{"seq":156472,"id":"CVE-2026-57160","ts":1789294596529,"field":"cvss","old":"5.3","new":"6.9"},{"seq":155267,"id":"CVE-2026-57160","ts":1789292791480,"field":"cvss","old":"6.9","new":"5.3"},{"seq":154062,"id":"CVE-2026-57160","ts":1789289592874,"field":"cvss","old":"5.3","new":"6.9"},{"seq":152712,"id":"CVE-2026-57160","ts":1789281522983,"field":"cvss","old":"6.9","new":"5.3"},{"seq":152352,"id":"CVE-2026-57160","ts":1789281123526,"field":"cvss","old":"5.3","new":"6.9"},{"seq":151313,"id":"CVE-2026-57160","ts":1789277536450,"field":"cvss","old":"6.9","new":"5.3"},{"seq":150274,"id":"CVE-2026-57160","ts":1789276110536,"field":"cvss","old":"5.3","new":"6.9"},{"seq":149241,"id":"CVE-2026-57160","ts":1789273738478,"field":"cvss","old":"6.9","new":"5.3"},{"seq":148208,"id":"CVE-2026-57160","ts":1789271126008,"field":"cvss","old":"5.3","new":"6.9"},{"seq":146243,"id":"CVE-2026-57160","ts":1789269282460,"field":"cvss","old":"6.9","new":"5.3"},{"seq":142855,"id":"CVE-2026-57160","ts":1789261369990,"field":"cvss","old":"5.3","new":"6.9"},{"seq":141686,"id":"CVE-2026-57160","ts":1789258742198,"field":"cvss","old":"6.9","new":"5.3"},{"seq":140527,"id":"CVE-2026-57160","ts":1789256582939,"field":"cvss","old":"5.3","new":"6.9"}]}