CVE-2026-28799 - PJSIP: Heap use-after-free in PJSIP presence subscription termination handler

CVE-2026-28799 - PJSIP: Heap use-after-free in PJSIP presence subscription termination handler

CVE ID : CVE-2026-28799 Published : March 6, 2026, 7:16 a.m. | 43 minutes ago Description : PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 6, 2026