CVE-2025-66443: Pexip Infinity

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

Affected products

  • Pexip Pexip Infinity: from 35.0, before 39.0 (fixed in 39.0)

Published 2025-12-25. Last modified 2026-10-07.