Executive brief
PJSIP is a multimedia communication library that provides VoIP/SIP calling capabilities for applications. When server verification is enabled, the library fails to properly validate TLS certificates containing DNS names with embedded NUL bytes, allowing an attacker with a trusted certificate to impersonate the legitimate server and intercept SIP sessions, including stealing login credentials. An attacker would need network access to intercept connections and a certificate issued by a trusted certificate authority.
Technical details
The OpenSSL and GnuTLS backends in pjlib's SSL socket implementation copy DNS SubjectAltName certificate attributes using strlen()-based string functions, which truncate at the first NUL byte and discard the explicit length returned by the underlying crypto libraries. This allows a certificate with a SAN like "victim.example\0.attacker" to be accepted for "victim.example" during hostname verification. The mbedTLS backend is unaffected because it preserves explicit string length during the copy operation. An attacker with a certificate from a trusted issuer who can intercept the TLS connection gains the ability to complete SIP handshakes and receive REGISTER credentials.
Affected products
- PJSIP PJSIP 2.17 and earlier
Timeline
- 2026-07-17: disclosed
- 2026-07-17: patched: Fixed on master in commit 43d3bd77bb6833eab4c493503b8d564a754ddfdd
- 2026-09-18: advisory