{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/pjsip/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pjmedia"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","voip","infrastructure"],"_cs_type":"advisory","_cs_vendors":["PJSIP"],"content_html":"\u003cp\u003eThe BSI has released an advisory regarding multiple vulnerabilities identified within the PJSIP pjmedia library. These security flaws allow a remote, unauthenticated attacker to initiate Denial of Service (DoS) conditions against services that utilize the affected media processing stack. PJSIP is a widely deployed open-source multimedia communication library used in numerous Voice over IP (VoIP) applications, softphones, and telecommunication infrastructure components. By sending specially crafted network traffic, an attacker can trigger crashes or resource exhaustion within the affected applications. Given the ubiquitous nature of PJSIP in real-time communication systems, organizations relying on softswitches, IP-PBX systems, or custom VoIP applications should review their software dependencies for the affected components and monitor for unexpected service interruptions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities leads to a denial of service state, causing affected telecommunications applications or services to crash or become unresponsive. This impact directly threatens the availability of real-time communication services, potentially affecting internal and external telephony operations, contact center availability, and emergency communication pathways. The scope of impact is dependent on the specific deployment architecture of the VoIP infrastructure using the vulnerable pjmedia library version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs for repeated application crashes or service restarts for any VoIP or communication applications utilizing PJSIP.\u003c/li\u003e\n\u003cli\u003eIdentify if any internal telephony or communication platforms incorporate the PJSIP pjmedia library.\u003c/li\u003e\n\u003cli\u003eContact upstream software vendors for internal VoIP and PBX solutions to determine if their products include the vulnerable version of PJSIP and when a security patch will be provided.\u003c/li\u003e\n\u003cli\u003eLimit exposure of VoIP signaling and media ports to trusted networks or authorized IP ranges to mitigate the risk of remote exploitation by unauthenticated actors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T13:37:27Z","date_published":"2026-08-04T13:37:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pjsip-dos/","summary":"Multiple vulnerabilities in the PJSIP pjmedia library can be exploited by a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting telecommunications services.","title":"Multiple Denial of Service Vulnerabilities in PJSIP pjmedia","url":"https://feed.craftedsignal.io/briefs/2026-08-pjsip-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - PJSIP","version":"https://jsonfeed.org/version/1.1"}