CVE-2026-26203
PJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented NAL
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.
| CWE | CWE-416 |
| Vendor | pjsip |
| Product | pjmedia-video |
| Published | Feb 19, 2026 |
| Last Updated | Feb 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for pjsip pjmedia-video
Be the first to know when new unknown vulnerabilities affecting pjsip pjmedia-video are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
pjsip / pjmedia-video
< 2.17