Linphone is a narrowly focused voice-over-IP and messaging platform whose vulnerability profile centers on its underlying SIP library, belle-sip, which handles protocol parsing and session negotiation. The observed weakness classes—HTTP request smuggling and improper resource management—reflect the complexity of reliably interpreting and disposing of network-protocol state in a real-time communications stack.
The number and severity of CVEs published that impact products developed by Linphone over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43611HIGH Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via " \ " in the display name of a From header. | Nov 12, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-43610HIGH Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via an invalid From header (request URI without a parameter) in an unauthenticated SIP message, a differe | Nov 12, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-33056HIGH Belledonne Belle-sip before 4.5.20, as used in Linphone and other products, can crash via an invalid From header in a SIP message. | Aug 12, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linphone.
Media articles that mention a CVE ID that affects a product developed by Linphone — matched by CVE ID, not by vendor name.