CVE-2026-57159High· 7.5▾ TwilightPJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
7.5 → 8.4
8.4 → 7.5
7.5 → 8.4
8.4 → 7.5
7.5 → 8.4
8.4 → 7.5
7.5 → 8.4
8.4 → 7.5
7.5 → 8.4
8.4 → 7.5
7.5 → 8.4
8.4 → 7.5
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978.
pjsip <= 2.17Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57161High· 8.2PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57166Medium· 5.3PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57165Medium· 5.3PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57160Medium· 5.3PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57164Medium· 5.9PJSIP is a free and open source multimedia communication library written in C
CVE-2026-93989Low· 3.1vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer()