CVE-2026-103109
Pexip · Published September 30, 2026
9.4
CVSS v3.1
CRITICALPatch availableGet patch
Description
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.
Affected Products
- Pexip Infinity < 38.2
- Pexip Infinity <= 39.1
- Pexip Infinity
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H