CVE-2026-57166
Last modified
CVE-2026-57166 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback for an entered command line. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback for an entered command line. Several command-line handling paths write an attacker-influenced amount of data into fixed-size buffers without sufficient bounds checking, so a long command line can overflow them. This affects only applications that enable the telnet CLI front-end (e.g. pj_cli_telnet_create() / --cli-telnet-port). The telnet CLI is an interactive administration interface with no authentication, so any client able to reach it can already issue arbitrary CLI commands. A malformed or overly long command line can overflow a fixed-size stack buffer while rendering command-line feedback, which may lead to application termination. Because reaching this code already requires access to the unauthenticated CLI, the impact beyond that existing access is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 4472a31.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Teluu | Pjsip | <= 2.17 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-57166?
How severe is CVE-2026-57166?
How do I fix CVE-2026-57166?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57160PJSIP is a free and open source multimedia communication lib…5.3
- CVE-2026-57161PJSIP is a free and open source multimedia communication lib…8.2
- CVE-2026-57162PJSIP is a free and open source multimedia communication lib…9.1
- CVE-2026-57163PJSIP is a free and open source multimedia communication lib…9.1
- CVE-2026-57164PJSIP is a free and open source multimedia communication lib…5.9
- CVE-2026-57165PJSIP is a free and open source multimedia communication lib…5.3
- CVE-2026-57167PeerTube is an ActivityPub-federated video streaming platfor…5.1
- CVE-2026-5717The VI: Include Post By plugin for WordPress is vulnerable t…6.4
- CVE-2026-57170Compliance-trestle (Trestle) is a Python SDK and command-lin…7.8
- CVE-2026-57171Compliance-trestle (Trestle) is a Python SDK and command-lin…7.7
- CVE-2026-57172DataEase is an open source data visualization and analysis t…8.3
- CVE-2026-5718The Drag and Drop Multiple File Upload for Contact Form 7 pl…8.1
Are you affected by CVE-2026-57166?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
