CVE-2026-25994: Pjsip

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

Affected products

  • Pjsip Pjsip: up to and including 2.16

Published 2026-02-11. Last modified 2026-06-17.