Unrated severityNVD Advisory· Published Mar 6, 2026· Updated Mar 9, 2026
PJSIP: Heap use-after-free in PJSIP presence subscription termination handler
CVE-2026-28799
Description
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.
Affected products
2- pjsip/pjprojectv5Range: < 2.17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/pjsip/pjproject/commit/e06ff6c64741cc1675fd3296615910f532f6b1a1mitrex_refsource_MISC
- github.com/pjsip/pjproject/security/advisories/GHSA-8fj4-fv9f-hjpcmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.