CVE-2026-34235 is a critical heap out-of-bounds read vulnerability in the PJSIP multimedia communication library, affecting versions prior to 2.17. Rated 9.1 CVSS, this flaw allows a remote attacker to achieve high confidentiality and availability impact with low attack complexity by sending crafted VP9 Scalability Structure data. While the vulnerability is on a "Hot List," it is not listed in CISA's KEV catalog, and there is no public exploit code or community discussion available, suggesting no active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.17CPE matchmatch criteria | cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.