๐Ÿ” CVE Alert

CVE-2026-26203

UNKNOWN 0.0

PJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented NAL

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.

CWE CWE-416
Vendor pjsip
Product pjmedia-video
Published Feb 19, 2026
Last Updated Feb 19, 2026
Stay Ahead of the Next One

Get instant alerts for pjsip pjmedia-video

Be the first to know when new unknown vulnerabilities affecting pjsip pjmedia-video are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

pjsip / pjmedia-video
< 2.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pjsip/pjproject/security/advisories/GHSA-p965-mf7j-gwv8 github.com: https://github.com/pjsip/pjproject/commit/5aee54f09d4f91538d55279d7316591b28fded6c