CVE-2026-84975: CWE-295: Improper Certificate Validation in pjsip pjproject
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with string functions that recalculate their length and truncate an embedded NUL byte. With server verification enabled through --tls-verify-server for the PJSIP TLS/SIPS transport, a certificate containing a DNS SubjectAltName formed from the target hostname prefix followed by an embedded NUL and an attacker-controlled suffix can therefore be accepted for the prefix hostname. An attacker who possesses such a certificate from a trusted issuer and can intercept the connection can impersonate the target server, complete the SIP session, and receive REGISTER credentials. The mbedTLS backend is not affected because it preserves the explicit string length. No fixed version is available as of this review.
AI Analysis
Technical Summary
PJSIP's OpenSSL and GnuTLS backends improperly handle DNS SubjectAltName fields by copying them with string functions that recalculate length and truncate embedded NUL bytes. When server verification is enabled via --tls-verify-server, a certificate with a DNS SubjectAltName consisting of the target hostname prefix followed by an embedded NUL and attacker-controlled suffix can be accepted as valid for the prefix hostname. This allows an attacker possessing such a certificate from a trusted issuer and capable of intercepting the connection to impersonate the target server, complete SIP sessions, and obtain REGISTER credentials. The mbedTLS backend avoids this issue by preserving explicit string lengths. No fixed version is available as of the current review.
Potential Impact
An attacker with a trusted certificate containing a crafted DNS SubjectAltName and the ability to intercept connections can impersonate the target server, potentially completing SIP sessions and capturing REGISTER credentials. This compromises confidentiality and integrity of SIP communications. The vulnerability does not affect availability. The mbedTLS backend is not vulnerable.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should be aware of the risk when using OpenSSL or GnuTLS backends with server verification enabled. Consider using the mbedTLS backend as it is not affected. Monitor vendor advisories for updates and patches. Avoid relying solely on TLS server verification in affected versions until a fix is released.
CVE-2026-84975: CWE-295: Improper Certificate Validation in pjsip pjproject
Description
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with string functions that recalculate their length and truncate an embedded NUL byte. With server verification enabled through --tls-verify-server for the PJSIP TLS/SIPS transport, a certificate containing a DNS SubjectAltName formed from the target hostname prefix followed by an embedded NUL and an attacker-controlled suffix can therefore be accepted for the prefix hostname. An attacker who possesses such a certificate from a trusted issuer and can intercept the connection can impersonate the target server, complete the SIP session, and receive REGISTER credentials. The mbedTLS backend is not affected because it preserves the explicit string length. No fixed version is available as of this review.
CVSS v3.1
Score 7.4high
Affected software
pjsip
pjproject
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PJSIP's OpenSSL and GnuTLS backends improperly handle DNS SubjectAltName fields by copying them with string functions that recalculate length and truncate embedded NUL bytes. When server verification is enabled via --tls-verify-server, a certificate with a DNS SubjectAltName consisting of the target hostname prefix followed by an embedded NUL and attacker-controlled suffix can be accepted as valid for the prefix hostname. This allows an attacker possessing such a certificate from a trusted issuer and capable of intercepting the connection to impersonate the target server, complete SIP sessions, and obtain REGISTER credentials. The mbedTLS backend avoids this issue by preserving explicit string lengths. No fixed version is available as of the current review.
Potential Impact
An attacker with a trusted certificate containing a crafted DNS SubjectAltName and the ability to intercept connections can impersonate the target server, potentially completing SIP sessions and capturing REGISTER credentials. This compromises confidentiality and integrity of SIP communications. The vulnerability does not affect availability. The mbedTLS backend is not vulnerable.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should be aware of the risk when using OpenSSL or GnuTLS backends with server verification enabled. Consider using the mbedTLS backend as it is not affected. Monitor vendor advisories for updates and patches. Avoid relying solely on TLS server verification in affected versions until a fix is released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-02T18:12:13.533Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aad759f55bf5e2cf54f35d5
Added to database: 09/18/2026, 17:32:15 UTC
Last enriched: 09/18/2026, 17:46:48 UTC
Last updated: 09/18/2026, 22:26:43 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.