Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.3
CVE-2026-57164: PJSIP HTTP client can overflow memory causing crashes
CVE-2026-57164 · published 1 month ago
Summary
The part of PJSIP that reads an entire HTTP response can allocate a buffer that is too small if the server’s reported size is wrong. A crafted response from a malicious or compromised server can make the program write beyond the allocated memory, leading to a crash or possible data corruption. Apply the latest update that includes the fix, or use the incremental read option and only connect to trusted servers.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | asterisk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | asterisk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | pjproject | All versions |
| – | pjsip | pjproject | < 8d5956afab2ede95ddb199078dc19a8ac0114f3d |
| – | teluu | pjsip |
<= 2.17 cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* |
Original advisory text
PJSIP: Heap overflow in the HTTP client
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applications that use the PJLIB-UTIL HTTP client to receive a whole response body at once (a completion callback with no incremental on_data_read callback). When growing the response buffer, an incorrect size calculation based on the server-supplied Content-Length can leave the buffer too small, causing response data to be written past the end of the allocation. A malicious or man-in-the-middle HTTP server can trigger this with a crafted response; impact may range from unexpected application termination to memory corruption. Applications that consume the response incrementally (via on_data_read), or that only connect to trusted servers, are not affected. This issue has been patched via commit 8d5956a.
References
- https://github.com/pjsip/pjproject/commit/8d5956afab2ede95ddb199078dc19a8ac0114f... Patch
- https://security-tracker.debian.org/tracker/CVE-2026-57164 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57164... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-57164 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-57164 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-57164 Third Party Advisory
- https://github.com/pjsip/pjproject/security/advisories/GHSA-59fr-724j-6fjv Patch Vendor Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
8.3
High
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published4 Sep 2026
Updated9 Oct 2026
First seen4 Sep 2026
Sources
CVE-2026-57164 · NVD
CVE-2026-57164 · MITRE
DEBIAN-CVE-2026-57164 · OSV
CVE-2026-57164 · OSV
GHSA-59fr-724j-6fjv · GHSA
UBUNTU-CVE-2026-57164 · OSV
Track software like this
Free during beta