Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-25994

44
FAUCET Score

CVE-2026-25994 is a critical buffer overflow vulnerability (CWE-120) in the PJNATH ICE Session component of the PJSIP multimedia communication library, affecting versions 2.16 and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service by supplying excessively long usernames during credential processing, as indicated by its CVSS score of 9.8 (Critical). While the vulnerability poses a significant risk with high impact on confidentiality, integrity, and availability, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.16CPE matchmatch criteria
cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.1HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.93%
Probability of exploitation in next 30 days
EPSS Percentile
77.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-52561 · May 14, 2026
This CVE's current EPSS score of 0.0193 is in the 66th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ansiblepatch availablevia llm_extracted
View patch
difypatch availablevia llm_extracted
View patch
freshrsspatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
ubuntupatch availablevia ubuntu_usn
Product: pjproject (bionic)Fixed in: 2.7.2~dfsg-1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: pjproject (xenial)Fixed in: 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1

Vendor Advisories (4)

ubuntuUSN-8122-1

PJSIP vulnerabilities

Mar 24, 2026
ansiblellm-ansible-fbeb988204c3c90d

USN-8122-1: PJSIP vulnerabilities

Mar 24, 2026
freshrssllm-freshrss-ec18400d4baf7a13

USN-8122-1: PJSIP vulnerabilities

Mar 24, 2026
difyllm-dify-4d5e7b1e8777bd46

USN-8122-1: PJSIP vulnerabilities

Mar 24, 2026

References

github.com / pjsip/pjproject/commit/063b3a155f163cc5a9a1df2c56b6720fd3a0dbb0
Patch
github.com / pjsip/pjproject/security/advisories/GHSA-j29p-pvh2-pvqp
PatchVendor Advisory