CVE-2026-28799Disclosure(pjsip / pjsip)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pjsip pjsip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pjsip

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pjsip

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-11: 103-0603-11
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure2Patch1
2026-03-111
General1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28799 (CVSS:8.7, HIGH) is Analyzed. PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f..https://nvd.nist.gov/vuln/detail/CVE-2026-28799 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A tweet references CVE‑2026‑28799 with a high CVSS score and a heap use‑after‑free before version 2.17, but contains no PoC, patch, or exploitation details.

    0000025
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28799 PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subs… https://www.cve.org/CVERecord?id=CVE-2026-28799

    Post summary

    The text announces a heap use‑after‑free flaw in PJSIP versions older than 2.17, linking to the CVE record for further details.

    00000145
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28799 Heap Use-After-Free Vulnerability in PJSIP Event Subscription Framework Before 2.17 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28799

    Post summary

    The text announces a new CVE (CVE‑2026‑28799) describing a heap use‑after‑free vulnerability in PJSIP, with no indications of PoC, exploit code, active exploitation, or patches.

    0000050
    4.0K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-28799: Unauthenticated SUBSCRIBE with Expires:0 triggers heap use-after-free in PJSIP ≤2.16, risking crash or code exec. Patch to 2.17 ASAP! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-28799 #VoIP #infosec #AppSec

    Post summary

    CVE-2026-28799 is a heap use‑after‑free flaw in PJSIP up to 2.16, potentially causing crashes or code execution. A patch is available in version 2.17 and should be applied immediately.

    0000052
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppjsippjsip---

Explore more