Loading
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-free vulnerability exists in PJSIP's event subscription framework (evsub.c) that is triggered during presence unsubscription (SUBSCRIBE with Expires=0). This issue has been patched in version 2.17.
Use CWE-416, Pjsip vendor hub and Pjsip product page to widen CVE-2026-28799 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-39269, CVE-2026-29068 and CVE-2026-40614 for nearby disclosures in the same product family.