CVE-2026-57163Critical· 9.1▾ MidnightPJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (t…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
9.1 → —
critical → none
— → 9.1
none → critical
9.1 → —
critical → none
— → 9.1
none → critical
9.1 → —
critical → none
— → 9.1
none → critical
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS handshake, an incorrect buffer-size value can cause an oversized SubjectAltName entry to be written past the end of a fixed-size stack buffer. A network-positioned attacker presenting a crafted certificate — a malicious server to a connecting client, or a malicious client to a server that requests certificates — can trigger this during the TLS handshake, before any SIP-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. This issue has been patched via commit c4a151a.
pjsip <= 2.17Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57161High· 8.2PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57162Critical· 9.1PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57166Medium· 5.3PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57165Medium· 5.3PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57160Medium· 5.3PJSIP is a free and open source multimedia communication library written in C
CVE-2026-57159High· 7.5PJSIP is a free and open source multimedia communication library written in C