CVE-2026-25994Patch(pjsip / pjsip)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pjsip pjsip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pjsip

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
pjsip

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-11: 2Mentions · 2026-06-17: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-02-11: 202-1106-17
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-112
Disclosure1Patch1
2026-06-171
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ Vulnerabilidades críticas no Asterisk (CVE-2025-65102, CVE-2026-25994, CVE-2026-26203) foram corrigidas no Debian 11. Saiba mais: -> http://tinyurl.com/3jv6bamn #Debian https://t.co/zqs5JVpber

    Post summary

    The tweet informs that critical Asterisk CVEs were patched in Debian 11, linking to the relevant advisory.

    1000065
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25994 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when … https://www.cve.org/CVERecord?id=CVE-2026-25994

    Post summary

    A buffer overflow exists in PJSIP 2.16 and earlier (CVE‑2026‑25994), affecting the PJNATH ICE Session; no exploitation, PoC, or patch details are provided.

    00000348
    56.5K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-25994: PJSIP up to 2.16 mishandles long ICE usernames, triggering a buffer overflow that can lead to remote code execution without authentication. Upgrade to 2.17 ASAP. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-25994 #VoIP #infosec #AppSec

    Post summary

    A buffer overflow in PJSIP versions up to 2.16 can allow unauthenticated remote code execution via long ICE usernames. Users are urged to upgrade to version 2.17 immediately, as detailed in the advisory.

    0000051
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppjsippjsip---

Explore more