CVE-2026-103109: Pexip Infinity

Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

Affected products

  • Pexip Pexip Infinity: before 38.2 (fixed in 38.2); from 39.0, up to and including 39.1; version 40.0 only

Published 2026-09-30. Last modified 2026-10-05.