OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103109

HIGH · CVSS 7.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Pexip Infinity versions prior to 38.2, as well as 39.0, 39.1, and 40.0, are vulnerable due to improper input validation in their media processing implementation. This flaw allows remote attackers to exploit crafted media streams, potentially leading to memory corruption or a denial of service through controlled software aborts. Organizations using affected versions should prioritize patching to mitigate the risk of service disruptions and potential exploitation.

CVE
CVE-2026-103109
Severity
HIGH
CVSS
7.7
EPSS
0.25%

Original NVD Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

Related CVEs

Other vulnerabilities affecting the same vendor(s)