CVE-2026-26967

PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing malformed SRTP packets, where the unpacketizer reads a 2-byte NAL unit size field without validating that both bytes are within the payload buffer bounds. The vulnerability affects applications that receive video using H.264. A patch is available at https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:26

Type Values Removed Values Added
Summary
  • (es) PJSIP es una biblioteca de comunicación multimedia de código abierto y gratuita escrita en C. En las versiones 2.16 e inferiores, existe una vulnerabilidad crítica de desbordamiento de búfer basado en montículo en el despaquetizador H.264 de PJSIP. El error ocurre al procesar paquetes SRTP malformados, donde el despaquetizador lee un campo de tamaño de unidad NAL de 2 bytes sin validar que ambos bytes estén dentro de los límites del búfer de carga útil. La vulnerabilidad afecta a las aplicaciones que reciben video usando H.264. Un parche está disponible en https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491.

20 Feb 2026, 19:30

Type Values Removed Values Added
CPE cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:*
First Time Pjsip
Pjsip pjsip
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491 - () https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491 - Patch
References () https://github.com/pjsip/pjproject/security/advisories/GHSA-x2hc-6969-g8v6 - () https://github.com/pjsip/pjproject/security/advisories/GHSA-x2hc-6969-g8v6 - Patch, Vendor Advisory

20 Feb 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 01:15

Updated : 2026-06-17 10:26


NVD link : CVE-2026-26967

Mitre link : CVE-2026-26967

CVE.ORG link : CVE-2026-26967


JSON object : View

Products Affected

pjsip

  • pjsip
CWE
CWE-122

Heap-based Buffer Overflow