#VU125900 Heap-based buffer overflow in pjsip - CVE-2026-32945
Published: April 14, 2026
pjsip
pjsip
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in the DNS parser's name length handler when parsing DNS records. A remote attacker can send a specially crafted DNS response to cause a denial of service.
Only applications using the PJSIP DNS resolver are affected, such as PJSUA or PJSUA2 when configured with a nameserver.