CVE-2026-29068Disclosure(pjsip / pjsip)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pjsip pjsip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched in version 2.17.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pjsip

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
pjsip

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-11: 103-0603-11
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure3Patch1
2026-03-111
General1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-29068 (CVSS:8.7, HIGH) is Analyzed. PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b..https://nvd.nist.gov/vuln/detail/CVE-2026-29068 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑29068, a high‑severity flaw in PJSIP before version 2.17, but does not provide any PoC, exploit, or patch details.

    0000028
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29068 PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-code… https://www.cve.org/CVERecord?id=CVE-2026-29068

    Post summary

    The text discloses a stack buffer overflow vulnerability in PJSIP versions earlier than 2.17, providing basic technical detail but no PoC, exploit, or mitigation information.

    00000143
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29068 Stack Buffer Overflow in PJSIP Multimedia Library Before Version ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29068 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A new stack buffer overflow vulnerability (CVE-2026-29068) affecting the PJSIP Multimedia Library has been disclosed with basic details, but no PoC, exploit code, active exploitation, or mitigation information is provided.

    0000052
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29068 - PJSIP: Stack buffer overflow in Opus codec parser Intel Report: https://ift.tt/bYtTe3J

    Post summary

    Intel releases a threat alert for CVE-2026-29068, describing a stack buffer overflow in PJSIP’s Opus codec parser.

    0000038
    343 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-29068: Remote stack buffer overflow in PJSIP codec parsing lets attackers crash apps or run code during RTP handling, no login needed. Upgrade to 2.17+ now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-29068 #VoIP #infosec #AppSec

    Post summary

    A remote stack buffer overflow in PJSIP codec parsing can crash applications or execute code without requiring authentication; upgrade to version 2.17+ to mitigate the vulnerability.

    0000051
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppjsippjsip---

Explore more