{"id":"CVE-2026-41415","summary":"PJSIP: SIP Multipart CID URI Length Underflow","details":"PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerability is fixed in 2.17.","aliases":["GHSA-935m-fmf5-j4pm"],"modified":"2026-08-12T16:24:12.659728Z","published":"2026-04-24T18:38:36.181Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41415.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41415.json"},{"type":"ADVISORY","url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-935m-fmf5-j4pm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41415"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/commit/4225a93c16661538005017883fbc8f1ea1d5f4b0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pjsip/pjproject","events":[{"introduced":"0"},{"fixed":"5a457451fa2712ba18e12b01738e8ff3af2b26fd"},{"fixed":"4225a93c16661538005017883fbc8f1ea1d5f4b0"}],"database_specific":{"cpe":"cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.17"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.16","2.15","2.14","2.13","2.12","2.11","2.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41415.json","vanir_signatures_modified":"2026-08-12T16:24:12Z","vanir_signatures":[{"source":"https://github.com/pjsip/pjproject/commit/4225a93c16661538005017883fbc8f1ea1d5f4b0","target":{"file":"pjsip/src/pjsip/sip_multipart.c","function":"cid_uri_to_hdr_value"},"deprecated":false,"digest":{"function_hash":"206450799826648084170189279271546504477","length":572},"id":"CVE-2026-41415-89ecbd61","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["79262952973521249288125243813768497841","337236539557385176214705682961713330037","236714100437145229605910874441205339013","23134313239600707680508713828761994841","75699548341151596935966092211537973180","152649484338712022001407900559978254884","124081537765448595130668561289207693168"],"threshold":0.9},"id":"CVE-2026-41415-ec778bc7","signature_type":"Line","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/4225a93c16661538005017883fbc8f1ea1d5f4b0","target":{"file":"pjsip/src/pjsip/sip_multipart.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U"}]}