CVE-2026-25994

CRITICAL

pjsip < 2.16 - Buffer Overflow in PJNATH ICE Session via Long Username

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-25994. PoCs published by vabismo452, adminlove520, VABISMO.

AI-analyzed exploit summary This is a functional exploit for CVE-2026-25994, a heap buffer overflow in PJPROJECT's PJNATH ICE session handling. The PoC sends a crafted SIP INVITE with an oversized 'ice-ufrag' attribute to trigger a stack overflow in pj_ice_sess_create_check_list().

Description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

Exploits (3)

exploitdb WORKING POC
by vabismo452 · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52561

This is a functional exploit for CVE-2026-25994, a heap buffer overflow in PJPROJECT's PJNATH ICE session handling. The PoC sends a crafted SIP INVITE with an oversized 'ice-ufrag' attribute to trigger a stack overflow in pj_ice_sess_create_check_list().

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: PJPROJECT (pjsip) <= 2.16
No auth needed
Prerequisites: Target running pjsip with ICE enabled · Network access to SIP port (default 5060)
devstral-2 · analyzed May 15, 2026 Full analysis →
github WORKING POC 3 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-25994

This repository contains a functional exploit PoC for CVE-2026-25994, a stack-based buffer overflow in the PJNATH ICE implementation of pjsip ≤ 2.16. The exploit sends a crafted SIP INVITE with an oversized ice-ufrag to trigger the overflow, with detailed technical analysis and a reliable crash mechanism.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: pjsip ≤ 2.16
No auth needed
Prerequisites: Network access to the target SIP server · Target running pjsip with ICE enabled
devstral-2 · analyzed May 04, 2026 Full analysis →
nomisec WORKING POC 1 stars
by VABISMO · poc
https://github.com/VABISMO/cve-2026-25994_PJSIP

This repository contains a functional exploit PoC for CVE-2026-25994, a stack-based buffer overflow in the PJNATH ICE implementation of pjsip ≤ 2.16. The exploit sends a crafted SIP INVITE with an oversized ice-ufrag to trigger the overflow, demonstrating the vulnerability.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: pjsip ≤ 2.16
No auth needed
Prerequisites: Target running pjsip with ICE enabled
devstral-2 · analyzed Apr 09, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0193
EPSS Percentile 77.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
pjsip/pjsip < 2.16
Published Feb 11, 2026
Tracked Since Feb 18, 2026