PJSIP Out-of-Bounds Read Vulnerability in SIP Multipart Message Parsing

Vulnerability

A vulnerability in PJSIP versions through 2.16 allows for an out-of-bounds read when handling a malformed Content-ID URI within SIP multipart message bodies. This issue arises from inadequate length validation, which can lead to reading data beyond the intended buffer limits.

Impact

Exploitation of this vulnerability could result in out-of-bounds read, potentially leading to memory corruption or disclosure of sensitive information.

Remediation

Users can upgrade to PJSIP version 2.17, where this vulnerability has been fixed.

Added: Apr 24, 2026, 8:54 PM
Updated: Apr 24, 2026, 8:54 PM

Vulnerability Rating

Custom Algorithm
spread
9.8
impact
0.6
exploitability
8.1
remediation
7.7
relevance
6.6
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.