CVE-2026-40892Disclosure(pjsip / pjsip)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pjsip pjsip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed digest credentials (PJSIP_CRED_DATA_DIGEST). The function copies credential data using cred_info->data.slen as the length without an upper-bound check, which can overflow the fixed-size ha1 stack buffer (128 bytes) if data.slen exceeds the expected digest string length.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pjsip

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
pjsip

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-27: 1Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-04-27: 104-2404-2705-31
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-271
Disclosure1
2026-05-311
Patch1
Full discourse3 posts
  • yottajunaid@yottajunaid
    Patch

    @BleepinComputer In order to get beyond MFA and steal session cookies, the exploit combines CVE-2026-40891 with a second flaw (CVE-2026-40892). This enables hackers to take over active VPN sessions without the need for passwords. Patch 6.2.5 or 6.3.3 right away, and terminate any open sessions.

    Post summary

    The post alerts users to CVE‑2026‑40891 and CVE‑2026‑40892, advising immediate patching of versions 6.2.5 or 6.3.3 to prevent potential VPN session takeover scenarios.

    00011748
    12 followersView on X
  • z3n@zench4n
    Disclosure

    Don't overlook the middleware layer. New CVEs in PJSIP (CVE-2026-40892) and FreeScout (CVE-2026-40496) highlight how legacy communication and help desk libraries remain prime targets for lateral movement in enterprise environments.

    Post summary

    The post announces two new CVEs (CVE-2026-40892 and CVE-2026-40496) in PJSIP and FreeScout, noting that legacy middleware remains a target for lateral movement but provides no technical, exploit, or mitigation details.

    1001047
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40892 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in P… https://www.cve.org/CVERecord?id=CVE-2026-40892

    Post summary

    The text announces a new stack buffer overflow vulnerability (CVE‑2026‑40892) affecting PJSIP 2.16 and earlier, with no evidence of exploitation or available patches.

    00010159
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppjsippjsip---

Explore more