CVE-2026-26203
Last modified
CVE-2026-26203 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pjsip | Pjsip | < 2.17 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-26203?
How severe is CVE-2026-26203?
How do I fix CVE-2026-26203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26198Ormar is a async mini ORM for Python. In versions 0.9.9 thro…7.5
- CVE-2026-26199HDF5 is a high-performance library and a file format specifi…6.5
- CVE-2026-2620A weakness has been identified in Huace Monitoring and Early…7.3
- CVE-2026-26200HDF5 is software for managing data. Prior to version 1.14.4-…7.8
- CVE-2026-26201emp3r0r is a C2 designed by Linux users for Linux environmen…7.5
- CVE-2026-26202Penpot is an open-source design tool for design and code col…7.5
- CVE-2026-26204Wazuh is a free and open source platform used for threat pre…5.5
- CVE-2026-26205opa-envoy-plugun is a plugin to enforce OPA policies with En…7.1
- CVE-2026-26206Wazuh is a free and open source platform used for threat pre…6.5
- CVE-2026-26207Discourse is an open source discussion platform. Prior to ve…5.4
- CVE-2026-26208ADB Explorer is a fluent UI for ADB on Windows. Prior to Bet…7.8
- CVE-2026-26209cbor2 provides encoding and decoding for the Concise Binary …7.5
Are you affected by CVE-2026-26203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
