CVE-2026-32942Disclosure(pjsip / pjsip)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between session destruction and the callbacks. This issue has been fixed in version 2.17.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pjsip

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pjsip

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 3Mentions · 2026-03-24: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-24: 103-2003-24
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure3
2026-03-241
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 PJSIP, Heap Use-After-Free, #CVE-2026-32942 (Critical) https://dailycve.com/pjsip-heap-use-after-free-cve-2026-32942-critical/

    Post summary

    The message announces CVE-2026-32942 as a critical heap use‑after‑free vulnerability in PJSIP, but provides no PoC, exploit, patch, or active exploitation details.

    0001030
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32942 PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session… https://www.cve.org/CVERecord?id=CVE-2026-32942

    Post summary

    A brief disclosure of CVE‑2026‑32942, noting a heap use‑after‑free flaw in PJSIP versions 2.16 and below, without any PoC, exploit, patch, or active exploitation mentioned.

    00000114
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32942 PJSIP Heap Use-After-Free Vulnerability in ICE Session Ma... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32942 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE‑2026‑32942, a PJSIP heap use‑after‑free vulnerability in ICE Session, and links to a detail page without mentioning a PoC, exploit code, active attacks, or remediation.

    0000042
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32942 - PJSIP has ICE session use-after-free race conditions Intel Report: https://ift.tt/QW5rKmI

    Post summary

    The message discloses CVE‑2026‑32942, a use‑after‑free race condition in PJSIP ICE sessions, and provides a link to an Intel report.

    0000031
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppjsippjsip---

Explore more