MEDIUM
pjsip
CVE published 2026-03-31
CVE-2026-34235
A heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer prior to version 2.17. This issue occurs when parsing crafted VP9 Scalability Structure (SS) data. Insufficient bounds checking on the payload descriptor length may cause reads beyond the allocated RTP payload buffer. The CVE record was published on 2026-03-31T16:16:32.767Z and has not been modified since then. Users of PJSIP v [truncated]