CVE-2026-25994 is a classic buffer overflow vulnerability in PJSIP, a free and open source multimedia communication library written in C. The issue affects PJSIP 2.16 and earlier and is located in the PJNATH ICE Session component while processing credentials containing excessively long usernames. Based on the provided information, insufficient bounds checking during handling or copying of the username field can cause memory corruption when an overlong credential value is processed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone exploit PoC for CVE-2026-25994 affecting the PJNATH ICE implementation in pjsip <= 2.16. It contains two files: a README describing the vulnerability, affected versions, exploitation conditions, and usage instructions; and a single Python script, pjsip-cve-2026-25994.py, which is the exploit entry point. The Python script is a synchronous UDP-based SIP sender. It constructs a realistic SIP INVITE with SDP content designed to reach the vulnerable ICE parsing path. The key malicious element is an oversized a=ice-ufrag SDP attribute containing 520 'A' characters, paired with a long a=ice-pwd value. The INVITE is sent to a configurable target IP and port, defaulting to 127.0.0.1:5060. The script retries a configurable number of times and treats a socket timeout as evidence that the target pjsua process likely crashed. Exploit capability is limited to denial of service / crash triggering. Although the README discusses possible RCE in theory, the provided code does not include any memory corruption primitives beyond the overflow trigger, no shellcode, no ROP, and no payload customization for code execution. As such, this is best classified as an operational crash PoC rather than a weaponized exploit. Notable protocol and target details extracted from the code include SIP URIs targeting localhost at the chosen IP/port, UDP transport, a spoofed local source of 127.0.0.1:15060 in SIP headers, and SDP media/candidate lines referencing 127.0.0.1:40000. The README also identifies the vulnerable function as pj_ice_sess_create_check_list() in pjnath/src/pjnath/ice_session.c and states that exploitation requires ICE to be enabled on the target application, such as pjsua started with --use-ice. Overall, the repository’s purpose is to demonstrate and reproduce a remotely reachable stack buffer overflow in pjsip’s ICE handling by sending a crafted SIP INVITE over UDP. It is concise, focused, and contains one executable exploit script plus documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.