CVE-2026-103109

Summary

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.

Affected Software

VendorProductVersion RangeStatus
PexipInfinity0 < 38.2.0affected
PexipInfinity39.0.0affected
PexipInfinity39.1.0affected
PexipInfinity40.0.0affected

Weaknesses

  • CWE-787: CWE-787 Out-of-bounds Write

References