PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.
Cite this page
CVE-2022-24786. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-24786
Use CWE-125, Pjsip vendor hub and Pjsip product page to widen CVE-2022-24786 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-39269, CVE-2026-29068 and CVE-2026-28799 for nearby disclosures in the same product family.