CVE-2026-40892 is a stack buffer overflow vulnerability in PJSIP version 2.16 and earlier, specifically in the pjsip_auth_create_digest2() function when processing pre-computed digest credentials. The flaw occurs because the function fails to validate the length of credential data before copying it into a fixed 128-byte stack buffer, allowing attackers to overflow the ha1 buffer if the credential data exceeds expected digest string lengths. The vulnerability carries a moderate risk profile with a FAUCET risk score of 40.0/100. While the specific CVSS vector is not available, stack buffer overflows typically present network-adjacent or local attack vectors with medium complexity, potentially enabling arbitrary code execution or denial of service depending on exploitation context and the affected application's privileges. Currently, CVE-2026-40892 is not listed as actively exploited in the Known Exploited Vulnerabilities (KEV) database, though it is flagged as Active on security tracking lists. The EPSS score of 0.0004 indicates this vulnerability has received relatively low community attention compared to the broader CVE population, suggesting either limited public exploit availability or constrained practical exploitability in real-world environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.17CPE matchmatch criteria | cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.