CVE-2026-26967
MEDIUMpjsip < 2.17 - Heap-based Buffer Overflow in H.264 Unpacketizer
Title source: llmDescription
PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing malformed SRTP packets, where the unpacketizer reads a 2-byte NAL unit size field without validating that both bytes are within the payload buffer bounds. The vulnerability affects applications that receive video using H.264. A patch is available at https://github.com/pjsip/pjproject/commit/f821c214e52b11bae11e4cd3c7f0864538fb5491.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/pjsip/pjproject/security/advisories/GHSA-x2hc-6969-g8v6
Scores
CVSS v3
5.3
EPSS
0.0029
EPSS Percentile
20.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-122
Status
published
Products (1)
pjsip/pjsip
< 2.17
Published
Feb 20, 2026
Tracked Since
Feb 20, 2026