CVE-2026-57160
CVE-2026-57160 is a medium-severity vulnerability in Teluu Pjsip with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-193.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v4: 6.9
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-193
- Affected product: Teluu Pjsip
- Published:
- Last modified:
Description
PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.
Frequently asked questions
- What is CVE-2026-57160?
- PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.
- How severe is CVE-2026-57160?
- CVE-2026-57160 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-57160 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-57160?
- CVE-2026-57160 affects Teluu Pjsip. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-57160?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-57160 published?
- CVE-2026-57160 was published on 2026-09-04 and last updated on 2026-09-11.
References
- https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c
- https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw
Affected products (1)
- cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*
More vulnerabilities in Teluu Pjsip
- CVE-2023-38703 — Critical (CVSS 9.8): PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#,…
- CVE-2022-31031 — Critical (CVSS 9.8): PJSIP is a free and open source multimedia communication library written in C language implementing standard based…
- CVE-2021-43303 — Critical (CVSS 9.8): Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer…
- CVE-2021-43301 — Critical (CVSS 9.8): Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause…
- CVE-2021-43300 — Critical (CVSS 9.8): Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a…
- CVE-2021-43299 — Critical (CVSS 9.8): Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a…
All CVEs affecting Teluu Pjsip →
Other CWE-193 (Off-by-one Error) vulnerabilities
- CVE-2024-10442 — Critical (CVSS 10.0): Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066,…
- CVE-2026-64047 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count…
- CVE-2026-53309 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions()…
- CVE-2026-53088 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in…
- CVE-2024-38441 — Critical (CVSS 9.8): Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to…
- CVE-2023-46853 — Critical (CVSS 9.8): In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used…