CVE-2026-32942 identifies a heap use-after-free vulnerability in PJSIP versions 2.16 and below, a widely used multimedia communication library. This flaw arises from race conditions during ICE session destruction and callbacks. Rated with a CVSS score of 8.1 HIGH, it is remotely exploitable over the network but requires high attack complexity, potentially leading to significant impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or notable community discussion, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.17CPE matchmatch criteria | cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.