CVE-2026-32945Disclosure(pjsip / pjsip)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pjsip pjsip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's built-in DNS resolver, such as those configured with pjsua_config.nameserver or UaConfig.nameserver in PJSUA/PJSUA2. It does not affect users who rely on the OS resolver (e.g., getaddrinfo()) by not configuring a nameserver, or those using an external resolver via pjsip_resolver_set_ext_resolver(). This issue is fixed in version 2.17. For users unable to upgrade, a workaround is to disable DNS resolution in the PJSIP config (by setting nameserver_count to zero) or to use an external resolver implementation instead.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pjsip

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
pjsip

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-20: 4Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-24: 103-2003-24
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-204
Disclosure3Patch1
2026-03-241
Disclosure1
Full discourse5 posts
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-32945: Heap overflow in PJSIP DNS parser lets remote attackers run code, no login needed. Upgrade to 2.17 or disable the built-in DNS resolver. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-32945 #VoIP #infosec #AppSec

    Post summary

    The advisory highlights CVE-2026-32945, a heap overflow in PJSIP’s DNS parser that enables remote code execution, and recommends upgrading to 2.17 or disabling the resolver to mitigate the risk.

    1001053
    55 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PJSIP, Heap-based Buffer Overflow, #CVE-2026-32945 (Critical) https://dailycve.com/pjsip-heap-based-buffer-overflow-cve-2026-32945-critical/

    Post summary

    A critical heap‑based buffer overflow vulnerability (CVE‑2026‑32945) has been disclosed in PJSIP, with technical details available via the linked dailycve article.

    0000031
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32945 PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parse… https://www.cve.org/CVERecord?id=CVE-2026-32945

    Post summary

    The post announces a heap‑based buffer overflow in PJSIP versions 2.16 and earlier, linking to the CVE record for further details.

    00000111
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32945 - PJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser Intel Report: https://ift.tt/9zZTEmO

    Post summary

    This alert announces CVE-2026-32945, a heap-based buffer overflow in PJSIP's DNS parser, without providing PoC, exploit, or remediation details.

    0000033
    334 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32945 Heap-Based Buffer Overflow in PJSIP DNS Parser Affecting Versions... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32945 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A heap‑based buffer overflow vulnerability (CVE‑2026‑32945) affecting PJSIP's DNS parser has been announced, with details available via the provided vulmon link.

    0000044
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppjsippjsip---

Explore more