SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-57159

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the PJSIP multimedia communication library, specifically in the SDP negotiator when the remote payload-type map maintenance feature is enabled. It allows for remote out-of-bounds read and write operations, potentially leading to memory corruption and denial of service, although code execution has not been demonstrated. Organizations that utilize PJSIP with this feature enabled should prioritize applying the patch to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57159
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978.

Related CVEs

Other vulnerabilities affecting the same vendor(s)