Description
Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.
Published: 2026-09-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via improper input validation
Action: Immediate Patch
AI Analysis

Impact

Pexip Infinity versions before 41.1 contain an improper input validation flaw in the media implementation. The vulnerability can be triggered by a remote attacker sending specially crafted input that causes the software to abort, resulting in a loss of service for all users. This flaw is reflected by CWE-617. The primary consequence is an interruption of communication services, potentially disrupting business operations that rely on Pexip for video conferencing and telepresence.

Affected Systems

The affected line of products is Pexip Infinity. Versions earlier than 41.1 are impacted. No specific patch version is provided in the CNA release notes, so any release equal to or greater than 41.1 should be considered protective.

Risk and Exploitability

The CVSS score of 7.5 indicates a high-severity denial of service vulnerability. While no EPSS score is available and the issue is not currently listed in the CISA KEV catalog, the lack of exploitation data does not diminish the risk of a denial of service event. Attackers can likely trigger the abort by delivering malformed media streams over an open network connection, as the flaw is triggered by remote input. Gaining critical access is not required; any remote party can exploit the flaw if the endpoint is reachable.

Generated by OpenCVE AI on September 30, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to version 41.1 or newer
  • Block or limit inbound media traffic from untrusted networks using network firewalls or ACLs
  • Implement monitoring for abrupt termination logs to detect exploitation attempts

Generated by OpenCVE AI on September 30, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Media Input Validation in Pexip Infinity

Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-617
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T13:54:56.703Z

Reserved: 2026-09-30T02:14:56.354Z

Link: CVE-2026-103099

cve-icon Vulnrichment

Updated: 2026-09-30T13:54:52.582Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T03:16:58.717

Modified: 2026-09-30T16:44:39.840

Link: CVE-2026-103099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:30:17Z

Weaknesses