HarborGuard / CVE
Back to search
HIGHCVE-2026-32942Published Modified CNA GitHub_M

CVE-2026-32942: PJSIP has ICE session use-after-free race conditions

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between session destruction and the callbacks. This issue has been fixed in version 2.17.

Metrics

CVSS v4.0
8.0
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • pjsip / pjproject
    < 2.17
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
CVE-2026-32942: PJSIP has ICE session use-after-free race conditions | HarborGuard CVE