Teluu maintains PJSIP, a widely embedded open-source VoIP and multimedia communications library whose narrow product scope belies significant reach across telephony, unified communications, and IoT platforms. The vendor's vulnerability footprint skews strongly toward critical-severity outcomes, driven by memory-safety weaknesses endemic to C-based protocol implementations: out-of-bounds reads and writes, classic buffer overflows, stack-based and heap-based overflow conditions recur across the library's session initiation protocol parsing and media handling layers. The concentration of critical flaws in a supply-chain component means that a single PJSIP vulnerability can propagate to every downstream product and device that embeds the library, amplifying the remediation burden across entire product families. Defenders should maintain an inventory of applications and devices that depend on this library rather than tracking the library alone, since patching often requires downstream vendors to rebuild and re-release their products. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teluu over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41415CRITICAL PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP mu | Apr 24, 2026 | 9.1 | 33 | NO | NO |
CVE-2022-23608CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Feb 22, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-37706CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected | Dec 22, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-43301CRITICAL Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack bu | Feb 16, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-31031CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Jun 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43303CRITICAL Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 c | Feb 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43300CRITICAL Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buff | Feb 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43299CRITICAL Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer | Feb 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-21723CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Jan 27, 2022 | 9.1 | 31 | NO | NO |
CVE-2017-16872CRITICAL An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the | Nov 17, 2017 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teluu.
Media articles that mention a CVE ID that affects a product developed by Teluu — matched by CVE ID, not by vendor name.