CVE-2020-13901: Meetecho Janus

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

Affected products

  • Meetecho Janus: from 0.3.0, up to and including 0.10.0

Published 2020-06-10. Last modified 2026-06-17.