CVE-2026-25994
CRITICALpjsip < 2.16 - Buffer Overflow in PJNATH ICE Session via Long Username
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2026-25994. PoCs published by vabismo452, adminlove520, VABISMO.
AI-analyzed exploit summary This is a functional exploit for CVE-2026-25994, a heap buffer overflow in PJPROJECT's PJNATH ICE session handling. The PoC sends a crafted SIP INVITE with an oversized 'ice-ufrag' attribute to trigger a stack overflow in pj_ice_sess_create_check_list().
Description
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.
Exploits (3)
This is a functional exploit for CVE-2026-25994, a heap buffer overflow in PJPROJECT's PJNATH ICE session handling. The PoC sends a crafted SIP INVITE with an oversized 'ice-ufrag' attribute to trigger a stack overflow in pj_ice_sess_create_check_list().
This repository contains a functional exploit PoC for CVE-2026-25994, a stack-based buffer overflow in the PJNATH ICE implementation of pjsip ≤ 2.16. The exploit sends a crafted SIP INVITE with an oversized ice-ufrag to trigger the overflow, with detailed technical analysis and a reliable crash mechanism.
This repository contains a functional exploit PoC for CVE-2026-25994, a stack-based buffer overflow in the PJNATH ICE implementation of pjsip ≤ 2.16. The exploit sends a crafted SIP INVITE with an oversized ice-ufrag to trigger the overflow, demonstrating the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H